Jump to content

fiza

Members
  • Posts

    6,750
  • Joined

Everything posted by fiza

  1. I may need to utilise Google password sync shortly. Any instructions and gotchas that you have would be greatly appreciated.
  2. You could ask the external users to create a Google account. They wouldnt have to create a new one they could use their existing hotmail etc and make that a Google account. When you go through the process of creating a new Google account the process gives you the option to "Use your existing email". In this way they can collaborate on Google docs using their existing email addresses and there is no 7 day window involved.
  3. Our Veeam does an offsite backup of the SIMS Server to a cloud repository so when I go to instant restore I get "No backup available on disk".
  4. To ensure I fully understand, do you have an isolated VM that you do a full SIMS server restore to and then just run SIMS client on that server to ensure all is good?
  5. I have set up a Google Form in Kiosk mode in the Google Admin Console so students cannot browse to anything else on the Chromebook. When the Chromebook is booting it give the option to press CTRL ALT S to bypass Kiosk mode. I don't want students to be able to bypass Kiosk mode or browse anywhere else. Is this possible?
  6. To those with SIMS, how do you test your backups to verify they are not corrupt and will be useful in the event that they are needed?
  7. The security keys are physical usb keys so no use with mobiles and we wanted to avoid teachers having to get mobiles out in class anyway.
  8. If we pre add security keys for staff, what about those that want to access emails on their mobile devices? Do you then allow them to set up another 2fa method for use on mobiles?
  9. Is there any way to prevent students from saving certain file types into their Google Drives? I know you can do attachment compliance in GMail but anything like that in Google Drive?
  10. Thanks but I meant on your Windows Domain.
  11. What access do you provide for your external SIMS Support company to allow them to support your SIMS installation including deploying upgrades to SIMS Database and workstations using SOLUS 3?
  12. Can you explain a little more how that works please? Your day to day tasks are done on the non domain physical PCs logged in with local accounts? What accounts do you use to remote int domain tech VMs? What level of admin privilege do these accounts have?
  13. How do you secure your jump boxes? I am looking to do this too but need some guidance on securing the workstation.
  14. Any Papercut admins able to tell me if it is possible to run a report on transactions carried out by a Papercut Admin? We need to see any topups made by one particular admin account on papercut. Having looked through the reports section of papercut i cant seem to find a report that will give me this info.
  15. Somehow managed to delete my original post!! Here it is again!
  16. I am leaning towards Synology NAS for onsite backups, more for retrieving deleted items that are more than 30 days old in shared drives. Which NAS and what size are people using for this purpose?
  17. Has the guidance been updated to say not to do this?
  18. We are customers but not had this information communicated to us yet.
  19. @Koldov I was always told that the PDC and RID Master should be on the same DC. In a single domain the Infrastructure Master has no work so can go on any DC. https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/fsmo-placement-and-optimization-on-ad-dcs
  20. Thankfully everything seems to be working as expected. @Oaktech was correct about 24hrs as DCDiag is now reporting all good. I am not 100% sure where the issue arose from but I still suspect the DC that I demoted as the other 2 are playing nicely now. Thanks for all the advice everyone.
  21. Since running that last command to reset the password the 2 DCs are now replicating but DC Diag is still showing the same error as above.
  22. When I run DCDIAG I get this error (I anonymised the domain name) An error event occurred. EventID: 0x40000004 Time Generated: 05/15/2023 15:14:56 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc2$. The target name used was LDAP/DC2.domain.com. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (DOMAIN.com) is different from the client domain (DOMAIN.com), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 05/15/2023 15:21:23 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc2$. The target name used was cifs/DC2.domain.com. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (DOMAIN.com) is different from the client domain (DOMAIN.com), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. ......................... DC1 failed test SystemLog I tried resetting the computer password by doing ; Deactivate the service “Key Distribution Center” Restart Domain Controller Start a command-box as administrator and enter the following command: netdom resetpwd /Server:Servername /userd:Domain Administrator /passwordd:Password Restart Domain Controller Reset the service “Key Distribution Center” to automatic start and start Where Servername is the DC with PDC role.
  23. Both showing correctly.
  24. I have DNS management working on both servers now. I am not sure I understand how to check if the server is pointing to itself as primary?
×
×
  • Create New...