Thursday, May 15, 2014

Virtualised Domain Controllers Replication Issues

I noticed virtualised domain controllers often have issues replicating new settings in Group Policy Objects. This warning message was also observed:

Error: 9036 (Paused for backup or restore)
After reading this Technet article on backing up virtual domain controller, I realised the cause was due to the snapshot back at Hyper-V level. The only supported backup method is running the backup job at the guest VM level. Since then, I've stopped backing up domain controllers at Hyper-V host level and disabled the backup integration services at VM configuration.

Monday, May 12, 2014

WS2012 Domain Controllers stop replication after Power Outage

We had some power outage and noticed newer Group Policy Objects (GPOs) weren't replicated across the AD. After running dcdiag /a diagnostic command, we noticed DRS-R event errors on some WS2012 Domain Controllers. After doing some research, we realised that WS2012 stopped auto-replication by default.

To enable it back, configure this setting on the registry and restart the affected DCs.

  1. Set HKLM\System\CurrentControlSet\Services\DFSR\Parameters\StopReplicationOnAutoRecovery registry key to a DWORD value of 0.
  2. On evelvated command prompt, run wmic /namespace:\\root\microsoftdfs path dfsrmachineconfig set StopReplicationOnAutoRecovery = FALSE

Thursday, May 8, 2014

Verify Domain Controller Certificate for Smartcard Logon

To enable user smartcard logon, all domain controllers must be enrolled with KDC enabled certificates. The correct cert template to deploy is Domain Controller Authentication. If you enrolled the domain controllers with wrong certs, you might encounter this error event on the domain controllers:
This event indicates an attempt was made to use smartcard logon, but the KDC is unable to use the PKINIT protocol because it is missing a suitable certificate.
To resolve, you'll have to delete the invalid cert and request for a new valid cert. To verify after enrolling domain controller certificates, run this command:
certutil -dcinfo verify
Reference: Event ID 19 — KDC Certificate Availability

Wednesday, April 9, 2014

Rebuilding WID Database for WSUS in Windows Server 2012

If you're using Windows Internal Database (WID) for WSUS in WS2012 and you think you've screwed the configuration, you can force the WSUS to rebuild its contents and database.

Steps:
  1. Remove WSUS and WID roles from server manager. Reboot server.
  2. Go to C:\Windows\WID\Data
  3. Move both "SUSDB.mdf" and "SUSDB_log.ldf" to another temp folder
  4. Re-install WSUS server role again
Found a comprehensive guide on http://prajwaldesai.com/troubleshooting-wsus-3-0-sp2-on-windows-server/

Files and Folders Copy with NTFS ACL Preservation

To bulk copy files and folders from one place to another and to preserve ACL permissions and folder structure, an easy way is to use Robocopy.exe like this:
> ROBOCOPY [source] [target] /MIR /SEC /SECFIX 
For example, to copy from local drive source to file share destination, the command should be
> ROBOCOPY D:\Shares \\UNC\Shares /MIR /SEC /SECFIX

Monday, March 17, 2014

How to clear old RMS Templates on FCI

If you're using FCI to perform automatic RMS encryption and you're setting up new RMS server, you'll find both old and new RMS templates appearing on the File Management Task like this:

How to remove and clear away old RMS templates? Clear all files under
C:\ProgramData\Microsoft\DRM\Server\Templates\S-1-5-18

Wednesday, March 12, 2014

Co-existence: Pre-production and Production AD RMS

We have developers wishing to develop AD RMS applications based on AD RMS SDK 2.1. Any applications developed out of this SDK is considered pre-production until its application manifest are signed with certs from Microsoft (a.k.a moving from pre-production to production).

However, pre-production applications won't work with production AD RMS server and vice-versa. Otherwise, you'll see this error: "Cannot use test manifests against production servers"

Hence, you'll have to follow this guide "How to install and configure an RMS Server" for pre-production. If there is already an existing RMS server in your AD, you've to re-setup this server for pre-production. It would effectively remove the production RMS server and Office RMS would stop working as a consequence. So, how can we make both RMS servers (one production server for Office RMS users and another pre-production for developer) to co-exist?

Our strategy is to setup a separate pre-production RMS server for developers to use that server. Remember that RMS clients would always refer to its registry settings before checking the AD SCP. Have the development PCs manually configured with pre-production server while the rest of Office clients refer to the SCP on Active Directory for the production RMS server.

Assuming that you already have a production RMS server, this is the outline plan:

  1. Prepare a new Windows server for AD RMS
  2. Prepare the registry settings on the new server for pre-production setup.
  3. Unregister existing SCP using RMS administrative toolkit
  4. Install the AD RMS role on the new pre-production server
  5. On the production RMS server, change the SCP back to its original URL