Koldov Posted July 26, 2022 Posted July 26, 2022 (edited) I've got 2 VMs up and running as DCs now and transferred FSMO roles to one of them (these sit on 2012R2 hosts unfortunately). 1. Should I raise the function level to 2016 now? 2. I can't view 'Effective Access' now on the 2012R2 server shares (from the 2012R2 server) "you do not have permission to evaluate effective access rights for the remote resource". I 'think' this is telling me that I can't view the properties as it has to look at the 2019 DC... why doesn't the Domain Admin have that permission? But when I try to view it from the 2019 servers it errors out telling me the RPC server is unavailable! 3. It seems I have broken scan to folder from our old Kyocera MFDs (the reason I was looking at 'Effective Access') to our 2012R2 file server... I have no idea why? It was working when the 2012R2 servers were DCs... So far Google has come up with a possible solution of adding 'Authenticated Users' into the 'Pre-Windows 2000 Compatible Access' group. EDIT: Also now having trouble with printer deployment again.... "Group Policy Object did not apply because it failed with error code '0x800704ec This program is blocked by group policy"... I thought it would have moved all the policies and groups over with the DC... Does anyone have a list of reg edits? Remind me again how it is worth upgrading... Edited July 26, 2022 by Koldov
mavhc Posted July 26, 2022 Posted July 26, 2022 Is your scanner so old it needs SMB1? If so get it upgraded, it's a security nightmare
Koldov Posted July 26, 2022 Author Posted July 26, 2022 (edited) I don't 'think' so... The Kyocera web portal for the MFD just says SMB on/off (it uses port 445 if that means anything). There isn't any way I could find to tell, but I'm pretty sure I've had SMBv1 turned off everywhere I could find for a while now (even on the 2012R2 servers). It does have this in the settings though: "Note : To use these settings, set the Authentication to the Network Authentication using this link. Authentication Settings" This takes me to an 'Authentication Settings' page where I can enter all sorts of domain info, but I've never needed to before... Just created a user, gave it permissions to the folder on the server and entered that info on the Kyocera... Edited July 26, 2022 by Koldov
Koldov Posted July 26, 2022 Author Posted July 26, 2022 Another question for anyone whose got this far... On the 'old' DCs I have still have Windows\SYSVOL_DFSR folders... do I need to keep them now?
Koldov Posted July 26, 2022 Author Posted July 26, 2022 Just to mention the last successful scan was on Friday 22/07/2022, so it's definitely something I've done this week taking out the 2012R2 DC and putting in a 2019 DC... I'm going to presume it's an extra something and is security related, but no idea what...
mavhc Posted July 26, 2022 Posted July 26, 2022 you can enable smb1 and see if that works as a temp fix, but it reduces your security, so get the photocopier people to install some firmware that's not ancient
Koldov Posted July 26, 2022 Author Posted July 26, 2022 No, I don't think it will make a difference, I'm sure SMBv1 has been disabled for a while.... Actually now my SIMS agents are not connecting back to server!
Koldov Posted July 26, 2022 Author Posted July 26, 2022 Ah, ok so I've just had a brainwave as I couldn't see SIMS firewall rules applied anymore... The old DCs have now gone from 'Domain Controllers' OU in AD, they have moved themselves into the 'built-in 'Computers' OU therefore no GPOs were applying!
Koldov Posted July 27, 2022 Author Posted July 27, 2022 Well, although that solved some of my issues (so far), the scan to folder issue persists.... and it's taken up too much of my time already (but needs to be sorted by the end of the week so I can't leave it). I have actually narrowed it down now (and it wasn't SMB as such), it appears the new 2019 DCs have actually taken notice of a GPO to block NTLM: I'm not about to stop blocking NTLM, but can't really find anywhere in the Kyocera settings to change this to Kerberos (if it is actually possible), the only setting there seemed to imply that the actual printer itself would need to authenticate by signing in to it with a domain user account (could have got that wrong but on a restart it was asking for a domain user)...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now