Wednesday, 4 February 2015

Functions Of NetLogon Service On Domain Controllers

This article explains the functions of NetLogon Service on 

domain controllers.


NetLogon Service is very important for Domain Controllers. This service is started and configured to start Automatic when you promote a server to Domain Controller. If this service is not running then there are a few things which fail. This article explains the functionality of NetLogon service on Domain Controllers as mentioned below:
·         This service is responsible for creating Secure Channel between Domain Controllers and client computers. Secure Channel is created to pass the authentication packets.
·         Service performs the registration of SRV records, CNAME and other DC records in the DNS Server to advertise the availability of Domain Controllers in the domain.
·         SRV Records registered by NetLogon Service are stored in C:\Windows\System32\Config\NetLogon.DNSFile.
·         Performs registration of SRV Records every 24 hours depending on the version of Operating System in use.

·         Registers the SRV Records for a site where there is no Domain Controller. This is called Site Coverege.

Windows Server 2008 Password Reset









Tuesday, 3 February 2015

Server 2008 event IDs that correspond to Windows Server 2003

The event ID numbering scheme changed for Windows 7, Server 2008, and Windows Vista. You might need to figure out the corresponding IDs so that you can use them with your monitoring software.


To find the Server 2008 event ID that corresponds to a given Server 2003 event ID, use the following simple rule:

Server 2003 event ID + 4096 = Windows Server 2008 Event ID.

Exceptions to this rule are the Windows logon events:
·         The successful logon events (event IDs 528 and 540) have been merged into a single event, 4624 (this is 528 + 4096).
·         The failure logon events (event IDs 529 through 537 and 539) have been merged into a single event, 4625 (this is 529 + 4096).

Sunday, 30 November 2014

DSQuery Commands

DSQuery

1) How to open DSQUERY GUI Window
rundll32 dsquery,OpenQueryWindow
2) To list all attributes for the specfic user
dsquery * -filter "samaccountname=vkr" -attr *
3) This command will list all DCs are associated with this site
dsquery server -o rdn -site SiteName
4) To List all users in the OU
dsquery user ou=test,dc=AP,DC=SSS,dc=com
5) To List all users and their home folder path in the OU.
dsquery user "ou=test,dc=ap,dc=sss,dc=com" | dsget user –hmdir
6) How to find all groups of a user is memberof without the DN's?
dsquery group -samid "groupname" | dsget group -members | dsget user -samid -c
"-c" will ignore the errors
7) User member of the group and their name
dsquery user -samid "admin" | dsget user -memberof -expand | dsget group -samid
8) How to find if the Domain Controller is a Global Catalog (GC) or not ?
dsquery server -name test1 | dsget server -isgc
9) How to find Schema version?
schupgr
10) How to find Site name by server name ?
dsquery server -name test1 | dsget server -site
11) How to find users logon name by their givenname for bulk users?
for /f %%x in (%1) do dsquery * domainroot -filter
(&(objectcategory=person)(objectclass=user)(givenName=%%x)) -attr sAMAccountName
Copy the above command to notepad save to bat file eg: User.bat
list the users givenname in txt file like user.txt run the bat file below
user.bat user.txt >> C:\report.txt
12) How to find subnet with associated site.
dsquery subnet -name 10.222.88.0/25 | dsget subnet
13) How to find SID of a user?
dsquery user -samid <bbiswas> | dsget user -sid
dsquery * -filter (samaccountname=santhosh) – attr sid
14)To get the members status from the active directory group
dsquery group -samid “Group Pre-Win2k Name” | dsget group -members | dsget user -disabled -display
15) Command to find all the subnets for the given site
dsquery subnet -o rdn -site <site name>
16) Command to find all DCs in the given site
dsquery server -o rdn -site <site name>
17) Command to find all DCs in the Forest
dsquery server -o rdn -forest
18) How to find all attributes for all users?
Dsquery * -limit 0 -filter "&(objectClass=User)(objectCategory=Person)" -attr * >>output123.txt
19) Find Person name starting with Kum and his SAM Accountname
Dsquery * -limit 0 -filter "&(objectClass=User)(objectCategory=Person)(name=kum*)" -attr samaccountname
20) Show How Many Times wrong Password has been entered on a specified domain controller.
dsquery * -filter "(sAMAccountName=jsmith)" -s MyServer -attr givenName sn badPwdCount
21) Find out Account Expiry date
dsquery user -name * -limit 0 | dsget user -samid -acctexpires
22) The command displays the DNS host name, the site name, and whether the server is Global Catalog (GC) server for each domain controller
dsquery server | dsget server -dnsname -site -isgc
23) Get all the servers in the forest
dsquery server -forest -limit 0 | dsget server -dnsname -site -isgc
24) Extract the all groups from an OU with Group Scope & Group Type. Find the below snap for your reference.
dsquery group "ou=test,dc=gs,dc=com" -limit 0 | dsget group -samid -scope -secgrp
25) How to find particular user attribute using LDAP Filter?
dsquery * -filter (samaccountname=biz) -attr name whenchanged
26) Get user information doing input file
FOR /F %a IN (C:\file.csv) DO dsquery user -samid "%a" | dsget user -fn –ln >> C:\result.csv
FOR /F %a IN (C:\temp\user.txt) DO dsquery group -samid "%a" | dsget group -members | dsget user -samid >> C:\temp\a.txt
dsquery * domainroot -filter "((objectCategory=Person)(objectClass=User)(sAMAccountName=Jon*))
-attr sAMAccountName userPrincipalName department
27) Add set of groups to user
FOR /F %a IN (C:\group.txt) DO dsquery user -samid apple | dsmod group %a -addmbr
28) Find computers DN
FOR /F %a IN (C:\computer.txt) DO dsquery computer -name %a
29) To get the user home directory
FOR /F %a IN (C:\user.txt) DO dsquery user -samid %a | dsget user -hmdir >> a.txt
30) To export all users in domain
"dsquery * -limit 0 -filter ""(&(objectCategory=person)(objectClass=user)
(!userAccountControl:1.2.840.113556.1.4.803:=2))"" -attr sAMAccountName displayName >>
 a.txt"

Sunday, 15 June 2014

Add domain group to local system/server Remote Desktop users Group and remove existing user which is associated with that group.




Add domain group to local system/server Remote Desktop users Group and remove existing user which is associated with that group.


How to Add Trusted Sites into IE through Group Policy

How to Add Trust Sites into IE before IE10 through Group Policy
Create Registry value
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\test.com]
"Http"=dword:00000002
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\orange.com]
"Http"=dword:00000002
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\apple.com]
"Http"=dword:00000002
Save it to TrustedSites.reg
Create Regadd.cmd file
And type it below
Reg import trustedsites.reg
Save the file

Copy these two files to logon folder where you want to implement ex TEST OU Users – User Configuration-policies-windows settings-scripts-logon.

Friday, 6 June 2014

User Account Lockouts Troubleshoot

User Account Lockouts:
                  1)     Identify the user information which domain controller user NT Account belongs to.
2)     Logon to the specific PDC server.
3)     Filter the event id 644 (User account lock info & 675 bad password info).
4)     Check if the user lockout information falls on the PDC, if user account locked out, you can see the information in the events and it will provide the Caller Machine Name, investigate the system which service is supplying bad password.

Typically the below reasons user passwords are getting locked out frequently.

Users Account Lockouts: Almost all User Account lockouts are due to a user changing their password and then encountering issues because the old password is still in use somewhere.
  1. The user has been logged into another workstation or server from before the time they recently changed their password.  Resolution: Logout, and then login with new password.
  2. The user has a Terminal Service session opened with the previous password credentials.  Resolution: Logon to the indicated server and close session or use Terminal Services Manager tool.
  3. The user has a previously mapped a drive using the previous password credentials.  Resolution: Recreate/Reset mapping with new credentials.
  4. The user has a service running under the context of their user account with the previous password credentials.  This service could be a standard service visible via the Services tool, or a scheduled job running via an AT job or Scheduled Jobs.  Resolution: Find the service and update the credentials.
  5. The indicated computer account has an application running that is utilizing the previous password.

When a local workstation is causing the lockouts, it may be necessary for the end-user to login while disconnected from the network and correct the issue.  They may have to even use their previous password to gain access to the session.