Showing posts with label Active Directory. Show all posts
Showing posts with label Active Directory. Show all posts

Monday, May 4, 2020

gMSA Account Configuration (PowerShell)


Step 1 - We need to create KDS root key. This need to run from the domain controller with domain admin or enterprise admin privileges. 

For production Environment use below command in PowerShell

Add-KdsRootKey –EffectiveImmediately

In testing environment use below command to remove the waiting time

Add-KdsRootKey –EffectiveTime ((get-date).addhours(-10))

To check whether it's created or not.

Get-KdsRootKey

Step 2 − Create below command to create gMSA user

New-ADServiceAccount “gmsauser” -DNSHostName “dc1.example.com”
-PrincipalsAllowedToRetrieveManagedPassword "gmsaGroup"

Step 3 – Use the below step to provide read access to the host server
a) Server Manager => Tools => Active Directory Administrative Center
b) locate created gmsa user
c) Security add each of the domain controllers with read access
d) SHOULD HAVE added the actual client machine.
f) Reboot each server including DCs

Step 4 − To install gMSA on a server → open PowerShell terminal and type in the following commands
ADServiceAccount – Identity gmsauser
ADServiceAccount gmsa1

Tuesday, November 7, 2017

What is Child domain


What is Child Domain:  

The concept of Child domain basically used for handling the replication issue and used if we want to segregate our business, it uses the name space of parent domain Eg: parent domain is “it.local”, the child domain will be “east.it.local”
  •  The trust relationship between child domain and parent domain will be two way Parent-Child trust, called transitive trust relationship.
  •  The Child domain do not contain Enterprise Admin Account .
  • The child domain shares both forest wide roles . 


                          


 



Monday, November 6, 2017

Bind Secondaries in DNS


Bind Secondaries used in DNS which  Allow  the Domain Name System (DNS) server to communicate with non-Microsoft DNS servers that use an earlier, slower version of the DNS BIND service. It basically use  compression, and it does contain  multiple records per  message during a connected transfer.

BIND version 4.9.4 and later version handles the fast zone transfer. We can change the BIND setting by using below steps

DNS server Properties(in DNS server)  -> Advanced Tab


Sunday, November 5, 2017

SOA (Start of Authority) Record

SOA (Start of Authority) Record is the preliminary part of a Zone file. It gives the information about the domain (how it updated, last update).
It holds the below fields:
  •   TTL
  • Serial Number
  •  Primary Server
  • Refresh Interval
SOA property is as below .

Sunday, July 17, 2016

How to Synchronise your time with the Domain Controller



Run the command Prompt As Administrator Mode :
Type the blow Command :
net time \\IP Of Domain Controller /set

Press Y

Featured post

System-preferred multifactor authentication (MFA)

Popular Posts