Jump to content

Recommended Posts

Posted

I have some random characters listed as users on 2 settings within my default domain controller policy. I assume they are old orphaned accounts that have been deleted.

 

Could some post up the accounts listed under these to sections, so I can check them against mine.

 

default domain controller policy///Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights\Assignment\Access this computer from the network

 

and

 

default domain controller policy///Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights\Assignment\Deny access to this computer from the network

 

Many thanks for your time

Posted
I have some random characters listed as users on 2 settings within my default domain controller policy. I assume they are old orphaned accounts that have been deleted.

 

Sounds like you're seeing a SID but without a screenshot I can't say for sure. If it is a SID you're seeing then you are correct in saying they are old/orphaned/deleted account that have been deleted.

  • Thanks 1
Posted (edited)
Best practice is to leave the default XXX GPO's alone, MS provide tools to recreate the default GPO's for those who do not take note of the best practice! here is one https://technet.microsoft.com/en-us/...(v=ws.11).aspx I think that there are some caveats if you are running Exchange.

 

I took over these servers from the local authority and the default XXX policies are full of changes onj not MS recommended in anyway. Doing the fix from your link would reset the policies, something that does need doing, but not at this moment as the fallout could be time consuming.

 

Originally I was getting this error when running AD best practice analyzer -

 

The Active Directory Domain Services Best Practices Analyzer (AD DS BPA) is not able to collect data about Group Policy Results setting "Access this computer from the network" from the domain controller.

 

When I delete the random characters from my test vm dc and run BPA its reports all fine.

 

What do you think, am I safe to delete them on the live server????

Edited by TwistedHelixis
Posted
Yeah they can just go, if they cannot be resolved to an account that still exists then that's a whole different set of issues right there! I had already guessed that you would not have been the perpetrator as you seem to be the one left holding the baby and the questions! good luck @TwistedHelixis
  • Thanks 1
Posted

Out of interest what do others have listed as the user in default domain controller policy///Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights\Assignment\Deny access to this computer from the network

 

LeMarchand has SUPPORT_ which is a user not listed on the server

I have random numbers from a deleted account

 

Just interested what it should actually be.

 

Cheers

Posted (edited)

Well something may have gone very BAD. I deleted the 2 accounts that no longer exist from 'Access this computer' default domain policy from the network at 2 schools without any problems but just done the same thing at a third and after running the best practice analyzer I am getting a load of errors. I stupidly did not run BPA before removing the orphaned accounts so not 100% sure if these errors have always been around but worried just in case they are new errors cause by me removing the orphaned accounts.

 

Hope someone can help as the list is overwhelming and I don't know where to start.

AD BPA Results

 

Information This domain controller must advertise as a KDC for the domain in its local site Configuration

 

Information This domain controller must advertise itself as a Kerberos server for the domain in its local site Configuration

 

Information This domain controller must advertise as a global catalog server for the forest in its local site Configuration

 

Information This domain controller must advertise as an LDAP server for the domain Configuration

 

Information This domain controller must advertise as a KDC for the domain Configuration

 

Information This domain controller must register its Rfc1510Kdc DNS record to advertise itself as Kerberos Server for the domain Configuration

 

Information This domain controller must register an alias (CNAME) resource record with its DsaGuid for the forest Configuration

 

Information This domain controller must register its Rfc1510UdpKpwd DNS record to advertise itself as Kerberos Server for the domain Configuration

 

Information This global catalog server must register its host (A/AAAA) resource records for the forest Configuration

 

Information This domain controller must advertise as a PDC for the domain Configuration

 

Information The schema master role and the domain naming master role should be owned by the same domain controller in the forest Configuration

 

Information This domain controller must register its DNS host A/AAAA records Configuration

 

Information The value of MaxPosPhaseCorrection on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should be equal to 48 hours Configuration

 

Information The PDC emulator master (SERVER)-vm-dc-01.(DOMAIN).lain this forest should be configured to correctly synchronize time from a valid time source Configuration

 

Warning All OUs in this domain should be protected from accidental deletion Configuration

 

Information The directory partition DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration

 

The directory partition CN=Schema,CN=Configuration,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration

 

Information The directory partition DC=DomainDnsZones,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration

 

Information No user accounts and trusts for the domain (DOMAIN).lan are configured for DES only Configuration

 

Information All trusted services within the domain (DOMAIN).lan have registered SPNs Configuration

 

Information The Default Domain Controllers Policy is applied to all OUs that contain domain controllers Configuration

 

Information Domain controller (SERVER)-vm-dc-01.(DOMAIN).lan must have "Enable computer and user accounts to be trusted for delegation" granted to the Builtin Administrators security group Configuration

 

Information Domain controller (SERVER)-vm-dc-01.(DOMAIN).lan must have "Access this Computer from the Network" granted to the appropriate security principals Configuration

 

Information No service accounts that are trusted for delegation in the domain (Domain).lan have duplicate SPNs Configuration

 

Warning The domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should comply with the recommended best practices guidelines because it is running on a VM Configuration

 

Information The directory partition DC=ForestDnsZones,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration

 

Information The directory partition CN=Configuration,DC=(SERVER),DC=lan on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should have been backed up within the last 8 days Configuration

 

Information The KCC should be enabled in each site in the forest (DOMAIN).lan Configuration

 

Information The resultant backup lifetime in this forest should be equal to or greater than 180 days Configuration

 

Information The value of MaxNegPhaseCorrection on the domain controller (SERVER)-vm-dc-01.(DOMAIN).lan should be equal to 48 hours Configuration

 

Information Strict replication consistency should be enabled on all domain controllers in this forest Configuration

 

Information The RID master role and the PDC emulator master role should be owned by the same domain controller in the domain Configuration

 

Warning All domains should have at least two domain controllers for redundancy Operation

 

Information This domain controller must advertise itself as a generic global catalog server for the forest Configuration

 

Information This domain controller must advertise as the global catalog server for the forest Configuration

 

Information This domain controller must register its Rfc1510Kpwd DNS record to advertise itself as Kerberos Server for the domain Configuration

 

Information This domain controller must register its Rfc1510UdpKdc DNS record to advertise itself as Kerberos Server for the domain Configuration

 

Information This server must advertise itself as a domain controller for the domain Configuration

 

Information This domain controller must register a DNS SRV resource record, which is required for replication to function correctly Configuration

 

Information This domain controller must register its DNS host (A or AAAA) resource records for the domain Configuration

 

Information This domain controller must advertise itself as a generic global catalog server for the forest in its local site Configuration

 

Information This server must advertise itself as a domain controller for the domain in its local site Configuration

 

Information This domain controller must advertise as an LDAP server for the domain in its local site Configuration

Edited by TwistedHelixis
Posted

UPDATE - Just fired up a VM backup of the DC on my test host server and did the same thing (deleted the random characters from the GP) but this time it has not got any errors. Hmmm not sure what to do now as I have nothing to fix on my test VM. I could just restore the VM DC onto the live host tonight.

 

Actually would have been more of a help if the test vm had the same issues.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...