Showing posts with label Active Directory. Show all posts
Showing posts with label Active Directory. Show all posts

Thursday, February 2, 2012

Join to Windows domain without connecting Domain server

Join to Windows domain without connecting Domain server

With Windows 7 and Windows Server 2008 R2, that process gets a bit shorter with the release of Microsoft's Offline Domain Join tool djoin.exe. This tool enables Windows 7 or Windows Server 2008 R2 computers to join a domain without needing to communicate with a domain controller (at least, at first). Exceptionally useful for massive desktop rollouts, this tool comes in particularly handy when automating the deployment of virtual desktops. Here's how you'll use it:

Step one requires the use of a domain-joined computer. This computer, which will be referred to as the provisioning computer, works with a domain controller to pre-populate information about the offline computer. From the provisioning computer, run the following command to create the necessary provisioning file:

djoin /provision /domain <domainName> /machine <offlineMachineName> /machineou <TargetOuToCreateAccount> /savefile <fileNameWithTxtExtension>

Running this command creates a text file that includes the necessary information for later adding this computer to the domain.

Step two involves copying the file you created in step one to the client computer, which has not been joined to the domain.

Step three completes the process by ingesting the information in the copied file into the offline client. This is done by running the following command on the offline client computer:

djoin /requestODJ /loadfile <fileNameWithTxtExtension> /windowspath %SystemRoot% /localos

Once complete here, reboot the computer to join it to the domain. You can further automate this process by adding a little scripting around the domain join steps, or even including its information in an unattend.xml file.

Thursday, March 31, 2011

How to enable Windows 2008 R2 Active directory Recycle bin


Firstly though the Active Directory Recycle Bin is not enabled by default and has certain domain and forest wide requirements before it can be enabled.
  • Firstly, all domain controllers within the Active Directory forest must be running Windows Server 2008 R2.
  • Secondly, the functional level of the Active Directory forest must be Windows Server 2008 R2.

For the ease of installation ,make sure that you are in Schema master or Domain naming master domain controller(Any or one among them will work)
Check this by using
C:\ netdom query fsmo

Errors

Enable-ADOptionalFeature : A referral was returned from the server
At line:1 char:25
+ Enable-ADOptionalFeature <<<<  -Identity `CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows
 NT,CN=Services,CN=Configuration,DC=mydomain,DC=com' -Scope ForestOrConfigurationSet -Target `mydomain.com'
    + CategoryInfo          : NotSpecified: (CN=Recycle Bin ...domain,DC=com:ADOptionalFeature) [Enable-ADOptionalFe
   ature], ADException
    + FullyQualifiedErrorId : A referral was returned from the server,Microsoft.ActiveDirectory.Management.Commands.En
   ableADOptionalFeature

Solution :
Just import the AD cmdlets into powershell first:
PS C:\Users\Sysadmin> import-module activedirectory

And then try


PS C:\Users\Sysadmin> Enable-ADOptionalFeature –Identity ‘CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=mydomain,DC=com’ –Scope ForestOrConfigurationSet –Target ‘mydomain.com’ 








Friday, March 18, 2011

FSMO transfer operation failed

By using the operations manager i get the following message:
"The transfer of the operations master role cannot be performed because:
The requested FSMO operation failed. The current FSMO holder could not be
contacted"

Solution :
I have restarted Netlogon and  it worked for me

Friday, February 18, 2011

Group policy -Points

  • Group Policies can be applied at multiple levels  Sites->domains-> organizational Units.To stop or control this flow we can use two options as below
  •  No Override - This prevents child containers from overriding policies set at higher levels
  • Block Inheritance - Stops containers inheriting policies from parent containers
  • No Override takes precedence over Block Inheritance so if a child container has Block Inheritance set but on the parent a group policy has No Override set then it will get applied. Also the highest No Override takes precedence over lower No Override's set.
  • There are two default GPOs in every Active Directory domain:
    • Default Domain Policy
    • Default Domain Controllers Policy
    • You change the group policies, and now the computer and user settings are in conflict. Which one has the highest priority?
  • Ans:The computer settings take priority.

GPO,GPT and GPC

GPO - Group Policy Object - Refers to the policy that is configured at the Active Directory level and is inherited by the domain member computers. You can configure a GPO – Group Policy Object - at the site level, domain level or OU level.
GPC – Group Policy Container:
This is the AD portion of group policy .The containers can be viewable using ADSI edit . It stores version information, status information, and other policy information. When you create a new GPO, an AD object of class groupPolicyContainer gets created under the System\Policies container within your AD domain
GPT - Group Policy Templates: The GPT is used for file-based data and stores software policy script, and deployment information. The GPT is located on the system volume folder of the domain controller. A GPO can be associated with one or more Active Directory containers such as a site, domain, or organizational.

How aging and scavenging works.

When ever a new system or entry added to a DNS server ,then the DNS server will keep a time stamp for that entry .then for then next 7 days (No-refresh interval )the server will not cross check this entry .after 7 days the dns server will try to get update from the client (Refresh time)for the next 7 days. The process of no-refresh +refresh interval is called aging  .If it does not get any response from the so called client, then it starts scavenge, means it will remove the entry from its database
DNS Monitoring tool

Global Catalog Server

A global catalog server is a domain controller it is a master searchable database that contains information about every object in every domain in a forest. The global catalog contains a complete replica of all objects in Active Directory for its host domain, and contains a partial replica of all objects in Active Directory for every other domain in the forest. It has two important functions:
Provides group membership information during logon and authentication
Helps users locate resources in Active Directory

Bridgehead Server


A bridgehead server is a domain controller in each site, which is used as a contact point to receive and replicate data between sites. For interstice replication, KCC designates one of the domain controllers as a bridgehead server. In case the server is down, KCC designates another one from the domain controller. When a bridgehead server receives replication updates from another site, it replicates the data to the other domain controllers within its site.

Important tools in Active Directory


Adsiedit.msc: Used to add, move and delete objects; and to change or delete object attributes.
Dcdiag.exe: Used to determine the state of domain controllers in the forest/enterprise.
Netdom.exe: Can be used to manage domains and trust relationships.
Repadmin.exe: Used to monitor, diagnose, and manage replication issues.
Esentutil.exe: This is to repair ntds.dit file which is the database of AD
Netdom : This is used to rename a domain controller,remove a member server/computer from domain ,And netdom query is to view details of computers in an OU etc

Replmon.exe: Used to monitor and manage replication through a graphical user interface (GUI).
Ntdsutil :
·         To manage FSMO roles like listing the FSMO Holders,Transfering and seiezing FSMO roles
·         Doing metadata cleanup
·         To reset Directory service restore password

Directory Services Restore Mode

Directory Services Restore Mode (DSRM) is a special boot mode for repairing or recovering Active Directory. It is used to log on to the computer when Active Directory has failed or needs to be restored.
To access Directory Services Restore Mode, you typically press F8 prior to the machine booting into Windows, then select the Directory Services Restore Mode option from the menu that appears.
For Remote Machine access the machine using  MSTSC and Edit  boot.ini file in Notepad.
Add the following line to the end of the boot.ini file:
/SAFEBOOT:DSREPAIR
Save and close the boot.ini file.
Reboot the server.

sysvol replication and AD Replication


The system volume contains scripts and group policies.Changes to SYSVOL are replicated to domain controllers within the same domain via File Replication System (FRS) replication. With FRS replication, the full file is replicated and not just the actual changes that were made to the file. This differs to Active Directory replication. With Active Directory only the changes that were made to Active Directory objects are replicated.

Active Directory Intrasite and Intersite Replication

Intrasite replication in Active Directory takes place between domain controllers within the same site. This makes intrasite replication an uncomplicated process. When changes are made to the replica of Active Directory on one particular domain controller, the domain controller contacts the remainder of the domain controllers within the site. The domain controller checks the information it contains against information hosted by the other domain controllers. To perform this analysis, the domain controller utilizes logical sequence numbers. Intrasite replication utilizes the Remote Procedure Call (RPC) protocol to convey replication data over fast, reliable network connections. With intrasite replication, replication data is not compressed.
Intersite replication takes place between sites. Intersite replication can utilize either RPC over IP or SMTP to convey replication data. This type of replication has to be manually configured. Intersite replication occurs between two domain controllers that are called bridgeheads or bridgehead servers. The role of a bridgehead server (BS) is assigned to at least one domain controller in a site. A BS in one site deals with replicating changes with other BSs in different sites. You can configure multiple bridgehead servers in a site. It is only these BSs that replicate data with domain controllers in different domains by performing intersite replication with its BS partners. With intersite replication, packets are compressed to save bandwidth. This places additional CPU load on domain controllers assigned the BS role. BSs should therefore be machines that have enough speed and processors to perform replication. Intersite replication takes place over site links by a polling method which is every 180 minutes by default.

What Is a Tombstone?


When Active Directory deletes an object from the directory, it does not physically remove the object from the database. Instead, Active Directory marks the object as deleted by setting the object’s isDeleted attribute to TRUE, stripping most of the attributes from the object, renaming the object, and then moving the object to a special container in the object’s naming context (NC) named CN=Deleted Objects. The object, now called a tombstone, is invisible to normal directory operations.
Obviously, objects don’t remain in the CN=Deleted Objects container forever. The default tombstone lifetime is 60 days for forests initially built using Windows® 2000 and Windows Server 2003, and 180 days for forests that were initially built with Windows Server 2003 SP1. Every 12 hours, each domain controller starts a garbage collection process. (This can be changed by setting a new value for the garbageCollPeriod attribute of the CN=Directory Service,CN=Windows NT, CN=Services,CN=Configuration,DC= object.) This garbage collection scans all of the tombstones on the DC and physically deletes any that are older than the tombstone lifetime.
The Deleted Objects container is hidden and cannot be viewed by using Active Directory Users and Computers and ADSIEDIT.MSC. But you can use LDP.EXE.

Note:There is another tool names ADRestore.exe which will do the same as LDP.exe

Authoritative and Non-Authoritative restore of an active directory

Non Authoritative  The default method of restoring an active directory is Non-Authoritative. This method will restore an active directory to the server in question and will then receive all of the recent updates from its replication partners in the domain. For example, a server that has a System State backup from two days ago goes down. A restore of the two-day old active directory would be performed and it would then be updated from the other domain controllers when the next replication takes place. No other steps would be required

Authoritative: This method restores the DC directory to the state that it was in when the backup was made, then overwrites all the other DC's to match the restored DC, thereby removing any changes made since backup. Authoritative restores do not have to be made of the entire directory, to restore only parts of the directory. When only parts of the active directory are restored, say an organizational unit, this information is pushed out to the remaining DC's and they are overwritten. However, the rest of the directory's information is then replicated to the restored DC's directory and it is updated

Wednesday, October 27, 2010

Active directory Delete a Failed Domain

To clean up metadata
  1. At the command line, type Ntdsutil and press ENTER.
C:\WINDOWS>ntdsutil
ntdsutil:
  1. At the Ntdsutil: prompt, type metadata cleanup and press Enter.
ntdsutil: metadata cleanup
metadata cleanup:
  1. At the metadata cleanup: prompt, type connections and press Enter.
metadata cleanup: connections
server connections:
  1. At the server connections: prompt, type connect to server <servername>, where <servername> is the domain controller (any functional domain controller in the same domain) from which you plan to clean up the metadata of the failed domain controller. Press Enter.
server connections: connect to server server100
Binding to server100 ...
Connected to server100 using credentials of locally logged on user.
server connections:
Note: Windows Server 2003 Service Pack 1 eliminates the need for the above step.
  1. Type quit and press Enter to return you to the metadata cleanup: prompt.
server connections: q
metadata cleanup:
  1. Type select operation target and press Enter.
metadata cleanup: Select operation target
select operation target:
  1. Type list domains and press Enter. This lists all domains in the forest with a number associated with each.
select operation target: list domains
Found 1 domain(s)
0 - DC=dpetri,DC=net
select operation target:
  1. Type select domain <number>, where <number> is the number corresponding to the domain in which the failed server was located. Press Enter.
select operation target: Select domain 0
No current site
Domain - DC=dpetri,DC=net
No current server
No current Naming Context
select operation target:
  1. Type list sites and press Enter.
select operation target: List sites
Found 1 site(s)
0 - CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
select operation target:
  1. Type select site <number>, where <number> refers to the number of the site in which the domain controller was a member. Press Enter.
select operation target: Select site 0
Site - CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
Domain - DC=dpetri,DC=net
No current server
No current Naming Context
select operation target:
  1. Type list servers in site and press Enter. This will list all servers in that site with a corresponding number.
select operation target: List servers in site
Found 2 server(s)
0 - CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
1 - CN=SERVER100,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
select operation target:
  1. Type select server <number> and press Enter, where <number> refers to the domain controller to be removed.
select operation target: Select server 0
Site - CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
Domain - DC=dpetri,DC=net
Server - CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
 DSA object - CN=NTDS Settings,CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net
 DNS host name - server200.dpetri.net
 Computer object - CN=SERVER200,OU=Domain Controllers,DC=dpetri,DC=net
No current Naming Context
select operation target:
  1. Type quit and press Enter. The Metadata cleanup menu is displayed.
select operation target: q
metadata cleanup:
  1. Type remove selected server and press Enter.
You will receive a warning message. Read it, and if you agree, press Yes.

metadata cleanup: Remove selected server
"CN=SERVER200,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dpetri,DC=net" removed from server "server100"
metadata cleanup:
At this point, Active Directory confirms that the domain controller was removed successfully. If you receive an error that the object could not be found, Active Directory might have already removed from the domain controller.
  1. Type quit, and press Enter until you return to the command prompt.

See http://www.petri.co.il/delete_failed_dcs_from_ad.htm for more details

Thursday, October 21, 2010

Issues if FSMO roles are not functioning properly

If one or more FSMO roles are not functioning properly ,there may be a lot of issues in the Domain enviornment. Let me note down important ones  among them




  1. Domain Naming Master
    1. Can't add or remove a domain - Changes to the namespace need this role holder.
    2. Can't promote or demote a DC - Changes to the namespace need this role holder.
 
  1. Schema Master
    1. Can't modify the schema - Changes to the schema need this role holder.
    2. Can't raise the functional level for the forest - This role holder must be available when the raising the forest functional level. 
      3  PDC Emulator
      1. Users can't log on - If system clocks become unsynchronized, Kerberos may fail.
      2. Can't change passwords - Password changes need this role holder.
      3. Account lockout not working - Account lockout enforcement needs this role holder.
      4. Can't raise the functional level for a domain - This role holder must be available when the raising the domain functional level.
       4   RID Master
    1. Can't create new users or groups - RID pool has been depleted.
        5  Infrastructure Master
    1. Problems with universal group memberships - Cross-domain object references need this role holder.

Transfering FSMO roles


Transfering FSMO roles

Microsoft didn’t  impose any rule for  keeping all 5 FSMO roles on same or different servers, But for obtaining maximum performance ,they recommend some suggested configurations.While installing a domain controller using dcpromo ,the first domain controller will hold all the 5 FSMO roles ,later while installing the second DC onwards we can transfer FSMO roles from the current holder to other.
We may need to transfer FSMO roles while demoting any of the DCs . when the original FSMO role holder went offline or became non operational for a long period of time, then we may need to do Seizing of FSMO roles.
However the transfer process is not initiated automatically by the operating system, for example a server in a shut-down state.
ou can transfer FSMO roles by using the Ntdsutil.exe command-line utility or by using an MMC snap-in tool.
Transferring the RID Master, PDC Emulator, and Infrastructure Masters via GUI
To Transfer the Domain-Specific RID Master, PDC Emulator, and Infrastructure Master FSMO Roles:
  1. Open the Active Directory Users and Computers snap-in from the Administrative Tools folder.
  2. If you are NOT logged onto the target domain controller, in the snap-in, right-click the icon next to Active Directory Users and Computers and press Connect to Domain Controller.
  3. Select the domain controller that will be the new role holder, the target, and press OK.
  4. Right-click the Active Directory Users and Computers icon again and press Operation Masters.
  5. Select the appropriate tab for the role you wish to transfer and press the Change button.
  6. Press OK to confirm the change.
  7. Press OK all the way out.
Transferring the Domain Naming Master via GUI
To Transfer the Domain Naming Master Role:
  1. Open the Active Directory Domains and Trusts snap-in from the Administrative Tools folder.
  2. If you are NOT logged onto the target domain controller, in the snap-in, right-click the icon next to Active Directory Domains and Trusts and press Connect to Domain Controller.
  3. Select the domain controller that will be the new role holder and press OK.
  4. Right-click the Active Directory Domains and Trusts icon again and press Operation Masters.
  5. Press the Change button.
  6. Press OK to confirm the change.
  7. Press OK all the way out.
Transferring the Schema Master via GUI
To Transfer the Schema Master Role:
  1. Register the Schmmgmt.dll library by pressing Start > RUN and typing:
regsvr32 schmmgmt.dll
  1. Press OK. You should receive a success confirmation.
  2. From the Run command open an MMC Console by typing MMC.
  3. On the Console menu, press Add/Remove Snap-in.
  4. Press Add. Select Active Directory Schema.
  5. Press Add and press Close. Press OK.
  6. If you are NOT logged onto the target domain controller, in the snap-in, right-click the Active Directory Schema icon in the Console Root and press Change Domain Controller.
  7. Press Specify .... and type the name of the new role holder. Press OK.
  8. Right-click right-click the Active Directory Schema icon again and press Operation Masters.
  9. Press the Change button.
  10. Press OK all the way out.

Wednesday, October 20, 2010

How to seize FSMO Roles

How to seize FSMO Roles

Open the command prompt and type ntdsutil
Eg:
C:\WINDOWS>ntdsutil
ntdsutil:

Step 2
T ype roles, and then press ENTER.

Eg:
ntdsutil: roles
fsmo maintenance:

Step :3
Type connections, and then press ENTER.

Eg:
fsmo maintenance: connections
server connections:

Step:4
Type connect to server <servername>, where <servername> is the name of the server you
want to use,and then press ENTER.

Eg
server connections: connect to server yourserver
Binding to yourserver ...
Connected to yourserver using credentials of locally logged on user.
server connections:
Step:5
At the server connections: prompt, type q, and then press ENTER again.
Eg:
server connections: q
fsmo maintenance:
Step:6
Type seize <role>, where <role> is the role you want to seize. For example, to seize the RID Master role, you would type seize rid master:
Available options are 
Eg
fsmo maintenance: ?
 ?                              - Show this help information
 Connections                    - Connect to a specific AD DC/LDS instance
 Help                           - Show this help information
 Quit                           - Return to the prior menu
 Seize infrastructure master    - Overwrite infrastructure role on connected server
 Seize naming master            - Overwrite Naming Master role on connected server
 Seize PDC                      - Overwrite PDC role on connected server
 Seize RID master               - Overwrite RID role on connected server
 Seize schema master            - Overwrite schema role on connected server
 Select operation target        - Select sites, servers, domains, roles and naming contexts
 Transfer infrastructure master - Make connected server the infrastructure master
 Transfer naming master         - Make connected server the naming master
 Transfer PDC                   - Make connected server the PDC
 Transfer RID master            - Make connected server the RID master
 Transfer schema master         - Make connected server the schema master

Step:6
After the selection of FSMO role You will receive a warning window asking if you want to perform the seize. Click on Yes.
Step 7:
Repeat steps 5 and 6 until you've seized all the required FSMO roles.
Step 8:
After you seize or transfer the roles, type q, and then press ENTER until you quit the Ntdsutil tool.
Note: Do not put the Infrastructure Master (IM) role on the same domain controller as the Global Catalog server. If the Infrastructure Master runs on a GC server it will stop updating object information because it does not contain any references to objects that it does not hold. This is because a GC server holds a partial replica of every object in the forest.