Explore Active Directory on Experts Exchange

Expert Solutions for Your Tech Problems

Active DirectoryActive Directory

Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identit...

Read more
  • 82K Content
  • 16K Contributors

Expert Spotlight
Top-Rated Plus Freelancer (Upwork)/EE Solution Guide / CEO / Photographer

Do it once, do it right and keep it simple
EE Awarded 2018
In the search of MVP
Powershell Expert
MCP / MCSE Messaging and Infrastructure

Article

Account lockout policies - The Good, The Bad and The Ugly

2
The following article deals with account lockout policies as you may find in (but not limited to) Windows domains. The issues discussed apply to all Windows domains whose authentication relies on passwords alone (as opposed to multifactor authentication).
Article

Quest Migration Manager (QMM) for MS Exchange - CAS FQDN Issue and Resolution

byMahesh
This article covers the Quest Migration Manager (QMM) for MS Exchange configuration issue with regards to CAS FQDN. Quest support docs are available to resolve some issues but don't cover the base issue. The Article should be useful to engineers working on Quest MS-Exchange migration projects.
Article
Deploy Teams Background via Active Directory

Teams - Deploy Team Background via Active Directory GPO

Microsoft Teams has begun to roll out the much anticipated Background Effects feature. This article describes how to deploy a custom Microsoft Teams backgrounds to users by leveraging Active Directory Group Policy File Preferences
Article

How to change display name of local Active Directory Users who are synced with AD users in Office 365 portal.

Lets take a scenario where all users in local AD has Display Name attribute set as surname, first name We need to set the same to First Name, Last Name
Article

ERROR_GEN_FAILURE [code 0x0000001f] When Attempting to Join vCenter to Active Directory

It is a common practice to join vCenter to Active Directory in order to enable AD logins and authentication to various virtual machines. However, there are times where this simple task fails. Fortunately, one of the most common reasons is due to an SMB1 issue and this describes how to resolve it.
Article
We have bitlocker ...so we need MBAM, too?

We have bitlocker ...so we need MBAM, too?

In this article, I will take a look at Microsoft Bitlocker Administration and Monitoring (“MBAM”) and conclude, why I prefer my own scripts for deployment and management.
Article

Delegation of access to Bitlocker Recovery Passwords – this way, please!

In this article, I will show you how delegation of control for Bitlocker recovery passwords in Active Directory is supposed to work using the common wizard, and why I think that you should do it differently.
Article

SHA1 to SHA2 Migration Needs, Prerequisites and available options

byMahesh
This article explains SHA1 to SHA2 migration requirements in a simple way by putting all data on table, while explaining SHA1 and SHA2 algorithms, SHA1 deprecation plans and possible migration paths to SHA2.
Article

ADCycleGroups - Multi-Level GPO Phase-In Tool

3
ADCycleGroups is a multilevel GPO phase-in tool I developed to automate the moving of computers and users from one GPO version to the next, until it finally gets to the latest GPO policy. This allows me to gradually move computers and users from one version of a policy to the next.
Article

Powershell script for AWS security group for Active Directory use

I had to put together a security group that conformed to Microsoft's requirements for Active Directory domain server use between an EC2 instance on AWS and domain servers in our private WAN. I was surprised there was no script for this and decided to put one together.
Article

Use Active Directory Images Anywhere

This is a simple web application that allows you to use Active Directory photos anywhere that you can use a HTML tag
Article

Computer Audit with Powershell

4
This article details my method of auditing computers by querying WMI class, serializing it to JSON and saving it is a central location, ready to be deserialized again and pulled into a report
Article

LAPS to KeePass

2
The "Local Administrator Password Solution" (LAPS) provides a centralized storage of secrets/passwords in Active Directory (AD). On the other hand, KeePass is an open source password manager. This Powershell script generates a KeePass XML file from a LAPS enabled Active Directory, ready for import.
Article

Microsoft Exchange Database Portability

byMahesh
In this article will discuss what Microsoft exchange database portability is and how we can use it to restore email services along with mailbox data in case of Exchange Server failures.
Article

Automatic logoff at schedule

6
Over time I have seen a number of questions asking how to logoff users at a specific time. I personally haven't required this but decided to develop a little Windows service that manages this via schedule and not a legacy scheduled task running shutdown /l or via AD logon hours
Article
AD SYSVOL Scratch recovery from backup

Active Directory System State Recovery with Sysvol Authoritative Restore (Authsysvol switch) Explained

byMahesh
This article explains AD System State Recovery with the authsysvol switch, what it does and when this restore should be attempted, prerequisites, demo, impact and implications. The topic is partially documented by Microsoft and DELL and lacks important details, hence tried to add entire stuff here
Article

Microsoft DFS-N and DFS-R Accidental Deletion Recovery

byMahesh
3
This article demonstrates DFS namespace and replication group accidental deletion recovery. DFS-N and DFS-R configuration are stored with active directory. Few precautionary measures will enable DFS-N and DFS-R recovery either from DFS native tool (dfsutil) or active directory.
Article

Pre Server 2016 Group Membership Expiration Tool

4
Group membership expiration is a superb new feature included with Active Directory 2016 functional level. But what if you want this functionality but you haven't upgraded yet? Since I have many clients that cannot yet leverage this new feature, I have developed a custom tool.
Article

Microsoft DFSR Issues and Resolution

byMahesh
1
In this article I will cover Microsoft DFSR major issues and their resolution. These issues can occur during initial deployment or post-deployment. The resolution for each problem is available on the internet generally in standalone posts. I have tried to present them here collectively and detailed.
Article
NTFS File Permissions

NTFS. Allow create, edit, and delete files but not create folders

byNVIT
An article explaining how to give user/group ability to create, edit, rename & delete files, but not create folders.

Do more with Experts Exchange.


Get Answers

Take a Class

Collaborate

Monitor your Site

Explore solutions and more