ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. active directory
    Log in to post
    • All categories
    • OksanaO

      How to Assess the Security of Your Active Directory

      Starwind
      • active directory ad pingcastle cyber security • • Oksana
      2
      1
      Votes
      2
      Posts
      538
      Views

      J

      Hmmmm.....

      There are two releases per year: January, 31th and July, 31th.
    • DustinB3403D

      Active Directory - User Attribute RFID/HID Badge

      IT Discussion
      • windows active directory azure rfid hid badge security attribute editor • • DustinB3403
      18
      0
      Votes
      18
      Posts
      2.5k
      Views

      DustinB3403D

      @Obsolesce said in Active Directory - User Attribute RFID/HID Badge:

      @DustinB3403 said in Active Directory - User Attribute RFID/HID Badge:

      @Dashrender I'm a 3rd party to the end customer here. Acting as the middle man as the customer's IT department wanted to engage outside support to try and vet different products.

      I candidly told the customer that while this product will work, it won't work with all of the features they want without some substantial changes to their infrastructure and that the support (at least from this vendor) is pretty awful.

      The simple approach here is to not integrate RFID/HID's to the system and simply use the AD Integration with the built-in QR codes that each member is assigned.

      Just because something may be supported, doesn't imply that it is support.

      Except in this case the vendor very clearly has stated they support you adding custom attributes within AD.

    • EddieJenningsE

      Managing Distribution Groups in an Exchange Hybrid Environment

      IT Discussion
      • exchange exchange 2013 exchange online office 365 active directory azure ad azure ad connect • • EddieJennings
      21
      0
      Votes
      21
      Posts
      6.6k
      Views

      EddieJenningsE

      @Dashrender said in Managing Distribution Groups in an Exchange Hybrid Environment:

      @EddieJennings said in Managing Distribution Groups in an Exchange Hybrid Environment:

      I ought to have clarified. DUO MFA comes into play with Outlook for our mailboxes that are in Exchange Online. On-prem mailboxes (the few we have left aren't subject to DUO).

      Are those that are left on prem - are they actual users? If so, I'm curious why they can't be migrated?

      Eventually all users will be migrated, so, yes, we still have real users on-prem.

      This is outside the scope of the original question / scenario, but I've learned a good bit during this process with much of that learning validating a few things I already knew, such as the value of taking the necessary time to plan, and prep the environment for migration (removing unnecessary objects, etc.).

    • scottalanmillerS

      Troubleshooting Azure AD Connect

      IT Discussion
      • azure ad ad connect active directory azure aad aad connect • • scottalanmiller
      14
      0
      Votes
      14
      Posts
      1.4k
      Views

      scottalanmillerS

      So far the rebuild appears to be still working. It ran all night. No complaints yet.

    • wirestyle22W

      Controlling Folder Depth when Exporting Folder ACL to Excel via Powershell

      IT Discussion
      • powershell active directory acl • • wirestyle22
      2
      1
      Votes
      2
      Posts
      1.3k
      Views

      ObsolesceO

      Try this instead:

      $FolderPath = Get-ChildItem -Recurse -Depth 2 -Path "P:\Public" -Force

      Where -Depth is the how many levels deep you want to go.

      If you want to see what a cmdlet can do, you can use:

      Get-Help Get-ChildItem -Full

    • OksanaO

      Template Your Windows VD Session Hosts

      Starwind
      • virtual desktop windows windows desktop azure ad azure active directory • • Oksana
      1
      1
      Votes
      1
      Posts
      390
      Views

      No one has replied

    • OksanaO

      Access and Distribute On-Prem IT Resources via Azure AD

      Starwind
      • azure ad azure active directory kerberos robo smb microsoft vpn • • Oksana
      1
      1
      Votes
      1
      Posts
      523
      Views

      No one has replied

    • OksanaO

      Migrating Azure Active Directory Connect

      Starwind
      • azure ad connect azure ad azure active directory office 365 • • Oksana
      1
      1
      Votes
      1
      Posts
      411
      Views

      No one has replied

    • S

      New to Windows Active Directory and Group Security Management

      IT Discussion
      • windows active directory • • srdennis
      13
      1
      Votes
      13
      Posts
      615
      Views

      DashrenderD

      @IRJ said in New to Windows Active Directory and Group Security Management:

      Make an AD group called workstation_admins and add that group to local administrators account on each desktop. This group does not need any AD rights and nobody's account should be in there except for IT admin accounts. Even those IT admin accounts should not be used on local desktops to login on a regular basis. Only when elevation is actually needed, and even then you should use run as.

      I do this - Those who need it have a workstation admin account and a local non admin normal account.

    • wrx7mW

      PowerShell - Using Variables to Delete SMTP Proxy Addresses in AD

      IT Discussion
      • powershell ad active directory windows get-aduser • • wrx7m
      11
      1
      Votes
      11
      Posts
      3.3k
      Views

      wrx7mW

      @flaxking said in PowerShell - Using Variables to Delete SMTP Proxy Addresses in AD:

      if they do not have previous experience with objects

      Describes me. lol

    • OksanaO

      AD FS Upgrade for Windows Server 2019

      Starwind
      • microsoft windows server 2019 active directory • • Oksana
      1
      2
      Votes
      1
      Posts
      251
      Views

      No one has replied

    • scottalanmillerS

      SAMIT: Do You Really Need Active Directory

      IT Discussion
      • samit scott alan miller youtube active directory • • scottalanmiller
      135
      1
      Votes
      135
      Posts
      12.0k
      Views

      coliverC

      @Dashrender said in SAMIT: Do You Really Need Active Directory:

      I am surprised that MS didn't come out with a better solution for this ages ago. That whole Direct Connect or whatever it was called - phone home VPN solution they have for Enterprise edition only - what a kluge.

      They are working on phasing this out. DirectAccess was a kludge that is being replaced by Always-On-VPN. Which works on versions of Windows Professional and Up and requires very little outside of a certificate and Group Policies (or Intune).

    • scottalanmillerS

      SAMIT: The Myth of Active Directory

      IT Discussion
      • samit youtube active directory scott alan miller • • scottalanmiller
      1
      1
      Votes
      1
      Posts
      398
      Views

      No one has replied

    • scottalanmillerS

      SAMIT: The False Risk of Active Directory

      IT Discussion
      • samit active directory scott alan miller youtube • • scottalanmiller
      1
      2
      Votes
      1
      Posts
      376
      Views

      No one has replied

    • IT-ADMINI

      How Can You Prevent Non-Domain Users from Getting an IP Configuration

      IT Discussion
      • active directory domain active directory network access control security networking • • IT-ADMIN
      16
      0
      Votes
      16
      Posts
      1.4k
      Views

      scottalanmillerS

      Discussion on the policy side of this is over here:

      https://mangolassi.it/topic/20894/policies-vs-network-access-control

    • K

      Anyone figured out how to ZeroTier with AD?

      IT Discussion
      • active directory zerotier vpn • • krisleslie
      88
      0
      Votes
      88
      Posts
      7.1k
      Views

      DashrenderD

      @krisleslie said in Anyone figured out how to ZeroTier with AD?:

      @Dashrender all ubnt

      They have two models, the unifi USGs and the EdgeRouter series - which are you sporting?

    • OksanaO

      Leave Microsoft access error behind!

      Starwind
      • active directory microsoft • • Oksana
      1
      1
      Votes
      1
      Posts
      212
      Views

      No one has replied

    • OksanaO

      Deploying Azure Active Directory Domain Services (AADDS)

      Starwind
      • azure active directory virtual machine • • Oksana
      1
      1
      Votes
      1
      Posts
      359
      Views

      No one has replied

    • anthonyhA

      Active Directory - Finding Source Of Repeated Lockouts

      IT Discussion
      • active directory gpo group policy • • anthonyh
      17
      1
      Votes
      17
      Posts
      1.5k
      Views

      anthonyhA

      A quick update for y'all that are watching/participating in this thread (thank you, by the way!).

      Late Friday I realized where the lockouts where coming from. We have a Windows VM that has a suite of applications that folks need to use every blue moon or so, and they access the VM via RDP. Of course, users don't log out, they just close the RDP client (I am going to fix this). The user in question had an old logon session on this VM. Killing the user's session (I just rebooted the VM) seems to have done the trick.

      Now the goal is to better position myself for the next time this happens. I also figure it's probably not a bad idea to have more visibility on account lockouts and where they are coming from in general.

    • wrx7mW

      Any Way to Automate Adding a New Computer to an AD Group?

      IT Discussion
      • windows 10 windows server ad active directory gpo mdt powershell ps pdq deploy ou task sequence • • wrx7m
      32
      0
      Votes
      32
      Posts
      8.5k
      Views

      F

      @marcinozga said in Any Way to Automate Adding a New Computer to an AD Group?:

      @flaxking said in Any Way to Automate Adding a New Computer to an AD Group?:

      @marcinozga said in Any Way to Automate Adding a New Computer to an AD Group?:

      Ansible can do that. https://docs.ansible.com/ansible/latest/modules/win_domain_group_membership_module.html#win-domain-group-membership-module
      You can add new PCs to domain, and change their group membership, you just need to know computer names in advance.

      Which is just a layer on top of Powershell. The Active Directory Powershell module is still required.

      It's not required, or that module is included already in Windows 10 by default. Because I haven't had to install it on any machine I managed with Ansible.

      "win_domain_group_membership requires the ActiveDirectory PS module to be installed"
      https://github.com/ansible/ansible/blob/devel/lib/ansible/modules/windows/win_domain_group_membership.ps1

      They have it in the documentation as well "This must be run on a host that has the ActiveDirectory powershell module installed."
      https://docs.ansible.com/ansible/latest/modules/win_domain_group_module.html

    • 1
    • 2
    • 3
    • 4
    • 5
    • 6
    • 7
    • 8
    • 2 / 8