Jump to content

mulbzh

Members
  • Posts

    21
  • Joined

  • Last visited

Everything posted by mulbzh

  1. after few months, still no problems since we migrated windows clients to last windows 11 version 🙂
  2. after migrated clients to 25H2, no more troubles in my company !
  3. From technician, the solution is to migrate clients to 25H2 as this resolve for us. But no explanation from Microsoft technician, i don't know what happen....
  4. Still no errors with 25h2, we are still waiting to be sure...
  5. No, i don't have GPO to set encryption configuration. Microsoft technician confirme, the DC can change himself this setting
  6. still no errors since we upgraded computers to 25H2
  7. few minutes after changed msDS-SupportedEncryptionType to 26, the attribute change back automatically to 28.... What i see, it is normal because DC see Keberos with RC4 so, the DC change to 28
  8. First action from the Microsoft technician today, on my controlers, he changed : msDS-SupportedEncryptionTypes from 28 to 26 on DC accounts, in attribute editor This change kerberos encryption type from RC4, AES 128, AES 256 to DES_CBC_MD5, AES 128, AES 256
  9. I am still testing with 25H2, still no more troubles for me.... Regarding Microsoft support, the technician doesn't care about me; he deliberately makes my phone ring only once, then sends an email saying: "I tried to contact you unsuccessfully to discuss the case," and he does this just before finishing his work. Then I immediately reply to his email, and the automatic response is: "I am not currently working...".
  10. we upgraded 50% of computers to 25H2, we are still testing, for the moment no troubles with this version but we have to test longer to be sure
  11. so bad Microsoft support... no solution for the moment and we said we are testing upgrade to 25H2. Microsoft technician tell : 'Ok, tell me if this resolve the troubles'. My response : we don't pay ticket for this, it is not the client who need to provide the solution.... 🙃
  12. yes sure because the first call with the technician, he said : 'so many troubles with windows 2025.... you should not migrate to windows 2025 !" and yes, i will post here solution from Microsoft
  13. ok thanks. So, for the moment the technician Microsoft still don't find the solution.... waiting...
  14. It is possible to have your script ? We test upgrade on computers to 25H2, for the moment it seems better... for the moment no relationship error
  15. For now, the Microsoft technician checked everything on domain controlers and computers and the configuration is OK. kerberos encryption is good, gpo, is good, DNS is good... He doesn't find the solution for the moment
  16. i am really lost about troubles with win 2025 and trust relationship. We don't find the solution, our computers and DC are up to date but still problems. We try also migrate some computers to last 25H2, but not better. Still kerberos errors security logs with ID 4771 : Kerberos pre-authentication failed. Command reset-computerMahcinePassword resolve temporarily , with GPO to disable password machine change it is not better. replication between DC is good, DNS records OK, time sync OK, ports open OK on DC We test also nltest /sc_verify:CONTOSO.local on DC. On one DC we have error but if i look at this article this seems normal : https://www.dell.com/support/kbdoc/en-us/000226052/domain we will open ticket to Microsoft...
  17. For me, i can't add new DC windows 2022 because i use new LAPS (legacy LAPS was uninstalled) and new LAPS is not available on windows 2022. I have to stay on windows 2025. I don't undertsand because staff computers works very well, no problem trust relationship but others computers have troubles. But it is the same OS version. But i sure it is because kerberos, i can see logs
  18. I found this KB for 24H2 : https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb [Authentication] This update addresses an issue affecting machine password rotation in the Identity Update Manager certificate/Public Key Cryptography for Initial Authentication (PKNIT) path. This issue occurred particularly when Kerberos was used and Credential Guard was enabled, potentially causing user authentication problems. The feature Machine Accounts in Credential Gurad, which is dependent on password rotation via Kerberos, has also been disabled, until a permanent fix is made available. but i have somes computer with 23H2, i don't find KB for this version
  19. Hello and sorry for my english, Same problem for me since i upgrade my DC from Win 2016 to win 2025 : trust relationship errors on some computers. Finally, there is KB by Microsoft for that or not ?
×
×
  • Create New...