Showing posts with label Active Directory. Show all posts
Showing posts with label Active Directory. Show all posts

Saturday, May 8, 2010

Troubleshooting Forest Trusts Batch Output

This is one of the batch files I put together to troubleshoot forest trust relationship problems.  It was based off a Microsoft Port Query template batch file.

@echo off
Goto START

************************************************************************
* Created By:  Linda Chapman
* CMD File to facilitate PortQry test for Domain Controllers
* INPUT SYNTAX: OpenPorts.cmd <DC NetBIOS name>
* OUTPUT: This will generate a <DC NetBIOS name>TrustedDomainResults.txt file.
* DEPENDENCY: PortQry.exe
*
************************************************************************

:START
echo.
echo Testing with PortQry against %%s
echo AD/DC specific ports
echo.
echo.

:ERRORCHECK

echo Press any key to continue the test...
pause

:PINGTEST
echo Pinging %%s
Echo    ************* > TrustedDomainResults.txt
Echo    * Ping Test * >> TrustedDomainResults.txt
Echo    ************* >> TrustedDomainResults.txt

for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do ping %%s >>TrustedDomainResults.txt
pause
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

:PORTWORK
echo Testing DNS
Echo    ************************ >> TrustedDomainResults.txt
Echo    * DNS (53) UDP and TCP * >> TrustedDomainResults.txt
Echo    ************************ >> TrustedDomainResults.txt
Echo    Performing    Portqry -n %%s -p both -e 53
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p both -e 53 >>TrustedDomainResults.txt
echo.
echo.
pause
echo Testing Kerberos
Echo    ***************************** >> TrustedDomainResults.txt
Echo    * Kerberos (88) UDP and TCP * >> TrustedDomainResults.txt
Echo    ***************************** >> TrustedDomainResults.txt
Echo     Performing  portqry -n %%s -p both -e 88 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do portqry -n %%s -p both -e 88 >>TrustedDomainResults.txt
echo.
echo.

echo Testing RPC End Point Mapper Service
Echo    ********************************** >> TrustedDomainResults.txt
Echo    * RPC End Point Mapper (135) TCP * >> TrustedDomainResults.txt
Echo    ********************************** >> TrustedDomainResults.txt
echo    performing portqry -n %%s -p TCP -e 135 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p TCP -e 135 >>TrustedDomainResults.txt
Echo.   >> TrustedDomainResults.txt
Echo.   >> TrustedDomainResults.txt
echo.
echo.

echo Testing NetBIOS Name Service
Echo    ********************* >> TrustedDomainResults.txt
Echo    * NetBIOS (137) UDP * >> TrustedDomainResults.txt
Echo    ********************* >> TrustedDomainResults.txt
echo   performing portqry -n %%s -p UDP -e 137 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p udp -e 137 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing NetBIOS Datagram Service
Echo    ********************* >> TrustedDomainResults.txt
Echo    * NetBIOS (138) UDP * >> TrustedDomainResults.txt
Echo    ********************* >> TrustedDomainResults.txt
echo    performing portqry -n %%s -p udp -e 138 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p udp -e 138 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing NetBIOS Session Service
echo    ********************* >> TrustedDomainResults.txt
Echo    * NetBIOS (139) TCP * >> TrustedDomainResults.txt
Echo    ********************* >> TrustedDomainResults.txt
echo    performingportqry -n %%s -p tcp -e 139 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p tcp -e 139 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing LDAP
Echo    ************************** >> TrustedDomainResults.txt
Echo    * LDAP (389) UDP and TCP * >> TrustedDomainResults.txt
Echo    ************************** >> TrustedDomainResults.txt
echo    performing portqry -n %%s -p both -e 389 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p both -e 389 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing SMB Direct Hosting
Echo    ***************** >> TrustedDomainResults.txt
Echo    * SMB (445) TCP * >> TrustedDomainResults.txt
Echo    ***************** >> TrustedDomainResults.txt
echo    performing portqry -n %%s -p tcp -e 445 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p tcp -e 445 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing Secure LDAP
Echo    ******************* >> TrustedDomainResults.txt
Echo    * LDAPS (636) TCP * >> TrustedDomainResults.txt
Echo    ******************* >> TrustedDomainResults.txt
echo    portqry -n %%s -p tcp -e 636 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p tcp -e 636 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing GC LDAP
Echo    ******************* >> TrustedDomainResults.txt
Echo    * LDAP (3268) TCP * >> TrustedDomainResults.txt
Echo    ******************* >> TrustedDomainResults.txt
echo    performing portqry -n %%s -p TCP -e 3268 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p tcp -e 3268 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.

echo Testing GC Secure LDAP
Echo    ******************** >> TrustedDomainResults.txt
Echo    * LDAPS (3269) TCP * >> TrustedDomainResults.txt
Echo    ******************** >> TrustedDomainResults.txt
Echo    Test GC SSL (3269) TCP >> TrustedDomainResults.txt
echo    performing portqry -n %%s -p tcp -e 3269 >> TrustedDomainResults.txt
for /f "eol=; tokens=1 delims=," %%s in (TrustedDomainServerList.txt) do Portqry -n %%s -p tcp -e 3269 >>TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
Echo. >> TrustedDomainResults.txt
echo.
echo.
echo End of Script
echo pause
Goto END

:END

Published: 4/30/2008 11:39 PM

How to view the current Operations Master role holders

Referenced Material

"www.microsoft.com/technet/solutionaccelerators/cits/mo/

winsrvmg/adpog/adpog5.mspx#EOBBG"

To view the current operations master role holders, use Ntdsutil.exe with the roles option. This option displays a list of all current role holders.

Procedure Requirements

  • Credentials: User or Administrator
  • Tool: Ntdsutil.exe (System Tools)

Procedure Steps

To view the current operations master role holder

  1. In the Run text box, type ntdsutil and press ENTER.
  2. At the ntdsutil: prompt, type roles and press ENTER.
  3. At the fsmo maintenance: prompt, type connections and press ENTER.
  4. At the server connections: prompt, type connect to server servername (where servername is the name of the domain controller that belongs to the domain containing the operations masters).
  5. After receiving confirmation of the connection, type quit and press ENTER to exit this menu.
  6. At the fsmo maintenance: prompt, type select operation target and press ENTER.
  7. At the select operations target: prompt, type list roles for connected server and press ENTER.
  8. The system responds with a list of the current roles and the Lightweight Directory Access Protocol (LDAP) name of the domain controllers currently assigned to host each role.
  9. Type quit and press ENTER to exit each prompt in Ntdsutil.exe. Type quit and press ENTER at the ntdsutil: prompt to close the window.

Published: 7/1/2008 9:14 PM

Migrations - IntraForest Domain Migration and Collapse

As a consultant, I have specialized in large enterprise migrations for 13 years.  Over that time I have lead the migration effort for over 10 large global enterprises all from complex mixed environments (MS, Unix, Novell, etc).  Below is the methodology I have developed over the years trying to follow all best practices.  This is my first article in a series of "Migration" topics.

The focus of this article is: Performing a IntraForest Domain Migration and Collapse using the free tool ADMT v3 (Active Directory Migration Tool).  This article does not take into consideration Exchange, SharePoint or any other application specifically.  It is a high level migration planning approach to get you started.

Important Concepts

  • The domain you are migrating or collapsing should be operating at Windows Server 2003 Functional Level.
  • Objects are migrated and no longer exist in the Source location.
  • SID history is required.  Using ADMT it will create a new SID but it will use the SID History or SID Walker old tool method to retain the original SID as an Attribute of the object, therefore AD is aware of the old SID.
  • Passwords are retained.
  • Local Profile Migration
    • Migrating user profiles is a completely separate step from migrating the user account.
    • Be prepared with the manual steps to migrate user profiles manually for ones that didn't work.
    • Users computer must be powered on and accessible on the network prior to the account, profile, and computer migration.
    • For workstations that run the Microsoft Windows 2000 Server operating system and later, local profiles are migrated automatically because the user’s GUID is preserved.
    • For Windows NT 4.0 and earlier you must use ADMT to migrate local profiles.
  • You must migrate accounts in closed sets. This means that all users in all groups you are migrating are only in your source domain, and all users that are in a group you are migrating are also being migrated, and all groups a user is in that is being migrated are being migrated. This is the only way the Global Group will be migrated to another Global Group.  If it is an "open set" then ADMT will migrate the Global Group to a Universal Group.  Remember, you don't want to have any more Universal Groups than necessary as they are replicated throughout the entire Trusted Forest structure from Global Catalog Server to Global Catalog Server causing un-necessary traffic over the network.
    • You migrate User Accounts, Global Groups together, and Resources (computers, servers, printers) and Local Groups together. The order you migrate objects is extremely important.  You will migrate Groups right before Users, not after.
    • When you migrate a Global Group it creates a Universal Group in the target domain to migrate the users into until all members of that Global Group have been migrated, and then it changes the Universal Group to a Global Group.  This is another reason it is important to migrate "closed sets".
  • Users must decrypt encrypted files before their account migration.

Active Directory Migration Tool

You must use ADMT to perform a domain migration or collapse properly. You can script it, use command prompt or use the Wizard.  Many things can go wrong in a migration using ADMT, especially if you have never performed a domain migration before.  Therefore, for this migration I highly suggest using the Wizard rather than scripting.

You will need to create at least one Migration Service Account that ADMT will use to perform the migration functions.

Object Migration Order

Remember you migrate 2 sets; 1) Groups and Users, and 2) Resources and Local Groups

  1. Run the Service Account Migration Wizard to identify all Service Accounts (it does not migrate them)
  2. Universal Groups
  3. Global Groups (exclude built-in groups)
  4. User Accounts that are members of the Global Groups migrated
    1. If you have any NT 4.0 computers then you need to Translate Local User Profiles next.
    2. This is not necessary for workstations > NT 4.0 because SID to GUID mapping will preserve in the registry the profile of the user and then re-associate it to the new SID.
  5. Service Accounts
  6. Resources - migrated users computers - you must reboot computer immediately afterwards
  7. Run Security Translation Wizard on any Software Distribution Points
  8. Resources - Printers
  9. Resources - File Servers - you must reboot immediately afterwards
  10. Resources - Member Servers (and Application Servers) - you must reboot immediately afterwards
  11. Resources - Infrastructure Servers (DHCP, DNS, all DCs except FMSO roles) and Domain Local Groups (exclude built-in groups) - you must reboot  immediately afterwards
  12. Resources - Infrastructure Server FSMO roles, leave the Root DC for last - you must reboot immediately afterwards

Migration Steps - high level

A domain migration and collapse is no minor task, and if not done in the proper order can orphan objects and lose their ACLs.  If you know me at all, you would know that I like to follow a phased approach for my migrations, as I was taught from my years work with Microsoft Consulting and EDS.

  1. Phase I - Preparation
    1. Clean up AD, remove all old user accounts, groups, OUs, computer accounts. 
    2. If you need to rename any accounts, groups or OUs you should do this prior to the migration, not during so that you do not experience naming conflicts.
    3. Identify all Login Scripts in the NTTL domain, track in a List recording what actions it takes.
    4. Identify all Service Accounts in the NTTL domain, track in a List recording; what permissions it requires, groups groups it is in, what GPOs are applied, and what applications and users use it.
    5. Identify all Domain Local Groups and ensure that the Domain Local Groups are NOT used ANYWHERE in the ACLs. 
      1. IMPORTANT:  Most companies do NOT leave enough time for this.  They "assume" that they don't have any or many ACLs using Domain Local Groups...and I have NEVER been to a company where they didn't under estimate this and ended up spending weeks re-ACLing at the last minute because they didn't address it properly.
    6. Identify all applications, scripts and batch files on all servers and workstations to ensure they do not have the fully qualified domain name hard coded anywhere.
      1. Again, I have stressed this to every customer and every customer insists they don't have any hard coded references to the domain names.  And again I have never had a customer that didn't have them.  I have had migrations come to a halt because of many domain references found at the last minute, that needed to be re-worked. 
      2. I suggest you purchase tool that can search the inside of batch files and other script files to search for your domain names.
    7. If there is currently only a one way trust, then create a two-way trust for the migration process as it just makes the steps easier.
    8. Identify all data, and printers on source domain controllers and migrate that data and objects over to other Member Servers if possible.
    9. Create a Service Account for ADMT that has Domain Administrator permissions in both domains.  It must also have delegated permission on the user, group, computer, OUs and the extended right to migrate SID history.
      1. In the TRI domain, delegate permissions on OUs that are targets for resource migration to the ADMT Service Account.
    10. OU Preparation - If you have a different OU structure then you will need to modify TRI to account for all computer, user, and application OUs.  You will need to map out which target OUs the computers and users will be migrated into.
  2. Phase II - Closed Set 1 Migration
    1. Use ADMT to migrate the following:
      1. Run the Service Account Migration Wizard to identify all Service Accounts (it does not migrate them)
      2. Universal Groups
      3. Global Groups (exclude built-in groups)
      4. User Accounts that are members of the Global Groups migrated
        1. If you have any NT 4.0 computers then you need to Translate Local User Profiles next.
        2. This is not necessary for workstations > NT 4.0 because SID to GUID mapping will preserve in the registry the profile of the user and then re-associate it to the new SID.
      5. Service Accounts
      6. Resources - migrated users computers - you must reboot computer immediately afterwards
    2. After each number verify migration logs for errors and verify the group types.
  3. Phase III - Closed Set 2 Migration
    1. Use ADMT to migrate the following:
      1. Run Security Translation Wizard on any Software Distribution Points
      2. Resources - Printers
      3. Resources - File Servers - you must reboot immediately afterwards
      4. Resources - Member Servers (and Application Servers) - you must reboot immediately afterwards
    2. After each number verify migration logs for errors and verify the group types.
  4. Phase IV - Collapse
    1. Use ADMT to migrate the following:
      1. Resources - Infrastructure Servers (DHCP, DNS, all DCs except FMSO roles) and Domain Local Groups (exclude built-in groups) - you must reboot  immediately afterwards
      2. Resources - Infrastructure Server FSMO roles, leave the Root DC for last - you must reboot immediately afterwards
      3. Perform ADMT Security Translation Wizard on Member Servers to clean up ACLs, and to remove the source domain SIDs from the ACLs..
    2. Only after ALL OBJECTS are migrated out of the child domain can you perform the DCPROMO back to a member server.
    3. Ensure all entries for the domain name and domain controllers are cleaned out of DNS, WINS, and Sites and Services properly.

Referenced Material:  Chapter 12 Restructuring Active directory Domains Within a Forest.doc

del.icio.us Tags: Migration Specialists,Active Directory migration,Active Directory Collapse,ADMT

Category: Active Directory;Migration

Published: 6/1/2008 9:11 PM

FSMO roles and how to transfer roles

In a forest, there are at least five FSMO roles that are assigned to one or more domain controllers. For best performance and recovery purposes you should not have all 5 FMSO roles on the same DC unless just to temporarily transfer to it for short-term maintenance. These are high level steps to transfer the Windows 2003 FSMO Roles to another DC for maintenance to be performed on the original DC.

For best performance and recovery purposes you should never have all 5 FMSO roles on the same DC unless just to temporarily transfer to it for short-term maintenance.

You can transfer FSMO roles by using the Ntdsutil.exe command-line utility or by using an MMC snap-in tool.

Depending on the FSMO role that you want to transfer, you can use one of the following three MMC snap-in tools:

  • · Active Directory Schema snap-in
  • · Active Directory Domains and Trusts snap-in
  • · Active Directory Users and Computers snap-in

If a computer no longer exists, the role must be seized. To seize a role, use the Ntdsutil.exe utility. Please use extreme caution when using this utility.

Transferring FSMO Roles – high level steps

Below are the high level steps required to perform any FSMO role transfers. What additional Change Management steps would be required would be determined following normal Change Management guidelines. At a minimum an RFC would always be required with a backup and restore plan.

If you have never transferred FSMO roles including the Schema Master role before you should perform this first in the lab. If you would perform a step out of sequence or when other DCs are not fully synchronized with the FSMO DCs you could have to revert to your back out plan.

  1. Go into Sites and Sites for that domain and force replication
  2. Check Event Viewer to see when the last reboot of both servers occurred, if over a week or prior to any other changes, then reboot both servers separately prior to proceeding to ensure stable after the reboot.
  3. Go into the Event viewer on all DCs and verify that Directory Services Replication has occurred successfully on all DCs, and no major errors on the target DCs. You can verify replication using EV or RepAdmin
  4. Verify all trusts are working using NLTest.exe
  5. Perform an NTBackup including System State and all drive data to an off disk location
  6. Verify that backup is restorable
  7. View and record the FSMO roles for the forest and target domain
  8. Transfer the Domain Naming Master Role
  9. Verify in Event Viewer or using NTDSutil, or MMC snap-in that the role transferred successfully.
  10. Go into Sites and Sites for that domain and force replication
  11. Verify successful replication to all DCs using Event Viewer, or repadmin /showrepl command, nltest, etc.
  12. Transfer RID Master, PDC Emulator, and Infrastructure Master Roles
  13. Verify in Event Viewer or using NTDSutil, or MMC snap-in that the role transferred successfully.
  14. Go into Sites and Sites for that domain and force replication
  15. Allow 30 minutes for all role changes to replicate throughout the forest, more if previously you found replication problems.
  16. Go into the Event viewer on all DCs and verify that Directory Services Replication has occurred successfully on all DCs, and no major errors on the target DCs. You can verify replication using EV or RepAdmin
  17. Transfer the Schema Master Role
  18. Verify in Event Viewer or using NTDSutil, or MMC snap-in that the role transferred successfully.
  19. Go into Sites and Sites for that domain and force replication
  20. Allow 30 minutes for all role changes to replicate throughout the forest, more if previously you found replication problems.
  21. Go into the Event viewer on all DCs and verify that Directory Services Replication has occurred successfully on all DCs, and no major errors on the target DCs. You can verify replication using EV or RepAdmin

Transferring FSMO Roles – Detailed Steps

The following steps to transfer FSMO Roles are from Microsoft white papers referenced below. These are not specific to any one environment, but are general steps.

Transfer the Domain Naming Master Role

  1. Click Start, point to Administrative Tools, and then click Active Directory Domains and Trusts.

  2. Right-click Active Directory Domains and Trusts, and then click Connect to Domain Controller.

  3. You must perform this step if you are not on the domain controller to which you want to transfer the role. You do not have to perform this step if you are already connected to the domain controller whose role you want to transfer.

  4. Do one of the following:

    • In the Enter the name of another domain controller box, type the name of the domain controller that will be the new role holder, and then click OK.

    • In the Or, select an available domain controller list, click the domain controller that will be the new role holder, and then click OK.

  5. In the console tree, right-click Active Directory Domains and Trusts, and then click Operations Master.

  6. Click Change.

  7. Click OK to confirm that you want to transfer the role, and then click Close.

Transfer the RID Master, PDC Emulator, and Infrastructure Master Roles

  1. Click Start, point to Administrative Tools, and then click Active Directory Users and Computers.

  2. Right-click Active Directory Users and Computers, and then click Connect to Domain Controller.

  3. You must perform this step if you are not on the domain controller to which you want to transfer the role. You do not have to perform this step if you are already connected to the domain controller whose role you want to transfer.

  4. Do one of the following:

    • In the Enter the name of another domain controller box, type the name of the domain controller that will be the new role holder, and then click OK.
    • In the Or, select an available domain controller list, click the domain controller that will be the new role holder, and then click OK.
  5. In the console tree, right-click Active Directory Users and Computers, point to All Tasks, and then click Operations Master.
  6. Click the appropriate tab for the role that you want to transfer (RID, PDC, or Infrastructure), and then click Change.
  7. Click OK to confirm that you want to transfer the role, and then click Close.

Transfer the Schema Master Role

It is very important that you ensure you have a complete backup and verified replication is successful on all DCs prior to transferring the Schema Master Role. If you have replication problems you could transfer the role and it not be accepted in the target DC or it accepts it and the remaining DCs still see the original schema master as still holding the role. This conflict would cause Forest wide problems potentially. So use with caution.

Use the Active Directory Schema Master snap-in to transfer the schema master role. Before you can use this snap-in, you must register the Schmmgmt.dll file.

Register Schmmgmt.dll

  1. Click Start, and then click Run.
  2. Type regsvr32 schmmgmt.dll in the Open box, and then click OK.
  3. Click OK when you receive the message that the operation succeeded.

Transfer the Schema Master Role

  1. Click Start, click Run, type mmc in the Open box, and then click OK.
  2. On the File, menu click Add/Remove Snap-in.
  3. Click Add.
  4. Click Active Directory Schema, click Add, click Close, and then click OK.
  5. In the console tree, right-click Active Directory Schema, and then click Change Domain Controller.
  6. Click Specify Name, type the name of the domain controller that will be the new role holder, and then click OK.
  7. In the console tree, right-click Active Directory Schema, and then click Operations Master.
  8. Click Change.
  9. Click OK to confirm that you want to transfer the role, and then click Close.

This document is based on the best practices for transferring FSMO Roles from Microsoft at:

http://support.microsoft.com/kb/324801

http://support.microsoft.com/kb/255690/

http://technet2.microsoft.com/WindowsServer/en/Library/ea7f8494-ee1e-4d99-b28f-8f2fd8a72df21033.mspx?mfr=true

Published: 1/4/2008 9:09 PM

Granular AD permissions and tools to accomplish it

Okay I will be unpopular with this...but I really can't stand it when a product/application says in their instructions that you must give the application account or service account local Administrator permissions...and the engineers believe it!

Recently I just did a short contract for software development company.  A name most of you have heard of.  I was extremely surprised at their huge lack of knowledge about the Microsoft products they were developing off the shelf software for.  Even when I showed them how to use a Service Account to run their app and how their app only needed read permissions in the place they were coding, they simply didn't care.  They insisted that "...we always state our application requires Domain Administrator privileges..." and they wouldn't stop. Need less to say for those that know me, I gave my notice and quit that contract.

Several years ago, I was on a Microsoft contract where we were applying the tightest security on our Microsoft servers. I was tasked with taking our entire application layer and determining what the lowest level permissions were actually needed for every service account and every application.  This of course took quite a bit of time in the lab, by me installing with the permissions the application owners said it needed (usually Administrator), then re-imaging and reinstalling with the individual permissions one by one until the install and application worked.  End result was there was absolutely no applications that we tested for our deployment that needed Administrator permissions. Some of the products I tested were; Veritas, Norton AV, several web applications, Office, Active Directory functions, DNS functions, Account and Server functions, and many other off the shelf products, including some Microsoft ones. Now this is not saying that none do.  If they don't take the time to code it right then it can.  But many don't even know themselves.

Vendors typically will say it needs Administrator permissions because they don't want to bother with testing the permissions one by one to see what exact granular permissions it needs.  Yes, even Microsoft has become worse about doing this.  Most applications only really need 4 NT rights to operate and those 4 rights added to an application account is what is a Service Account.  There are some that need some other additional privileges of course too.

If you want a tighten down environment you will always take the time to test the actual granular permissions needed, and never believe the vendor when they say it takes Administrator. 

ALSO, I come across so many engineers that will test it using the built-in groups (Administrators, Backup Operators, Account Operators, etc)  and say...see it only worked when I added the account into the Administrators group.  Open your eyes and learn your operating system better.  There are about 35+ granular permissions you can grant...but you have to use the proper tools to grant or remove them!  This is probably not a complete list either, but the two tools I use the most often to get the granular permissions needed.

DSacls found in the Support Tools

   Permissions

  • GR - Generic Read
  • GE - Generic Execute
  • GW - Generic Write
  • GA - Generic All
  • SD - Delete
  • DT - Delete an object and all its child objects.
  • RC - Read security information
  • WD - Change security information
  • WO - Change owner information
  • LC - List the child objects of an object
  • CC - Create child object. If {Object|Property} is not specified to define a specific property, this applies to all properties of an object. Otherwise, it applies to the specified property of the object.
  • DC - Delete child object. If {Object|Property} is not specified to define a specific property, this applies to all properties of an object. Otherwise, it applies to the specified property of the object.
  • WS - Write to self object. If {Object|Property} is not specified to define a specific property, this applies to all properties of an object. Otherwise, it applies to the specified property of the object.
  • RP - Read property. If {Object|Property} is not specified to define a specific property, this applies to all properties of an object. Otherwise, it applies to the specified property of the object.
  • WP - Write property. If {Object|Property} is not specified to define a specific property, this applies to all properties of an object. Otherwise, it applies to the specified property of the object.
  • CA - Control access right. If {Object|Property} is not specified to define a specific property, this applies to all properties of an object. Otherwise, it applies to the specified property of the object.
  • LO - List the object access. Can be used to grant list access to a specific object if List Children (LC) is not also granted to the parent. Can also be denied on specific objects to hide those objects if the user or group has LC on the parent. By default, Active Directory does not enforce this permission.

NTrights.exe found in the Resource Kit

  • SeTcbPrivilege
    Act as part of the operating system
    Allows a process to authenticate like a user and thus gain access to the same resources as a user. Only low-level authentication services should require this privilege.
  • SeMachineAccountPrivilege
    Add computers to a domain
    Allows the user to add a computer to a specific domain. For the privilege to be effective, it must be assigned to the user as part of local security policy for domain controllers in the domain.
  • SeBackupPrivilege
    Back up files and directories
    Allows the user to circumvent file and directory permissions to back up the system. The privilege is checked only when an application attempts access through the NTFS backup application programming interface (API). Otherwise, normal file and directory permissions apply.
    • By default, this privilege is assigned to Administrators and Backup Operators. See also Restore files and directories in this table.
  • SeChangeNotifyPrivilege
    Bypass traverse checking
    Allows the user to pass through folders to which the user otherwise has no access while navigating an object path in any Windows file system or in the registry. This privilege does not allow the user to list the contents of a folder; it allows the user only to traverse its directories.
    • By default, this privilege is assigned to Administrators, Backup Operators, Power Users, Users, and Everyone.
  • SeSystemTimePrivilege
    Change the system time
    Allows the user to set the time for the internal clock of the computer.
    • By default, this privilege is assigned to Administrators and Power Users.
  • SeCreatePagefilePrivilege
    Create a page file
    Allows the user to create and change the size of a page file.
    • By default, this privilege is assigned to Administrators.
  • SeCreateTokenPrivilege
    Create a token object
    Allows a process to create an access token by calling NtCreateToken() or other token-creating APIs.
  • SeCreatePermanentPrivilege
    Create permanent shared objects
    Allows a process to create a directory object in the Windows 2000 or Windows Server 2003 object manager.
  • SeRemoteShutdownPrivilege
    Force shutdown from a remote system
    Allows a user to shut down a computer from a remote location on the network. See also Shut down the system in this table.
    • By default, this privilege is assigned to Administrators.
  • SeAuditPrivilege
    Generate security audits
    Allows a process to create, generate, and add entries in the security log. The security log is used to track unauthorized system access. See also Manage auditing and security log in this table.
  • SeIncreaseQuotaPrivilege
    Increase quotas
    Allows a process that has Write Property access to another process to increase the processor quota that is assigned to the other process. This privilege is useful for system tuning, but it can be misused, as in a denial of service attack.
    • By default, this privilege is assigned to Administrators.
  • SeIncreaseBasePriorityPrivilege
    Increase scheduling priority
    Allows a process that has Write property access to another process so that it can increase the execution priority of the other process. A user with this privilege can change the scheduling priority of a process in the Task Manager dialog box.
    • By default, this privilege is assigned to Administrators.
  • SeLoadDriverPrivilege
    Load and unload device drivers
    Allows a user to install and uninstall Plug and Play device drivers. Device drivers that are not Plug and Play are not affected by this privilege and can be installed only by Administrators. Because device drivers run as trusted (highly privileged) programs, this privilege can be misused to install hostile programs and give them destructive access to resources.
    • By default, this privilege is assigned to Administrators.
  • SeLockMemoryPrivilege
    Lock pages in memory
    Allows a process to keep data in physical memory, which prevents the system from paging the data to virtual memory on disk. Exercising this privilege can significantly degrade system performance. This privilege is obsolete and should therefore never be selected.
  • SeSecurityPrivilege
    Manage auditing and security log
    Allows a user to specify object access auditing options on individual resources such as files, Active Directory objects, and registry keys. Object access auditing must first be enabled in Audit Policy (under Security Settings, Local Policies). With this privilege a user can then specify individual objects for auditing in Windows Explorer. A user who has this privilege can also view and clear the security log from Event Viewer.
    • By default, this privilege is assigned to Administrators.
  • SeSystemEnvironmentPrivilege
    Modify firmware environment values
    Allows modification of system environment variables either by a process through an API or by a user through System Properties.
    • By default, this privilege is assigned to Administrators.
  • SeProfileSingleProcessPrivilege
    Profile a single process
    Allows a user to run Windows 2000® and Windows Server 2003 performance-monitoring tools to monitor the performance of nonsystem processes.
    • By default, this privilege is assigned to Administrators and Power Users.
  • SeSystemProfilePrivilege
    Profile system performance
    Allows a user to run Windows 2000 and Windows Server 2003 performance-monitoring tools to monitor the performance of system processes.
    • By default, this privilege is assigned to Administrators.
  • SeAssignPrimaryTokenPrivilege
    Replace a process-level token
    Allows a parent process to replace the access token associated with a child process.
  • SeRestorePrivilege
    Restore files and directories
    Allows a user to circumvent file and directory permissions when restoring backed-up files and directories and to set any valid security principal as the owner of an object. See also Back up files and directories in this table.
    • By default, this privilege is assigned to Administrators and Backup Operators.
  • SeShutdownPrivilege
    Shut down the system
    Allows a user to shut down the local computer. See also Force shutdown from a remote system in this table. In Windows XP Professional:
    • By default, this privilege is assigned to Administrators, Backup Operators, Power Users, and Users. In Windows Server 2003 :
    • By default, this privilege is not assigned to Users, only to Administrators, Backup Operators, and Power Users.
  • SeTakeOwnershipPrivilege
    Take ownership of files or other objects
    Allows a user to take ownership of any securable object in the system, including Active Directory objects, files and folders, printers, registry keys, processes, and threads.
    • By default, this privilege is assigned to Administrators.

Published: 7/25/2007 9:06 PM

Scripts - Creating Users, Home Directories, Shares

This batch file is one that I created many years ago, but still use.  It is a simple non-complicated way to automatically create users, apply a password, create their home directory and home share.  Your list of users have to be one to a line in the referenced u:\user.txt  file.  There are many different ways you can script something like this.  I use this on contracts where they don't have someone that can support a script but could a simple batch file.

rem    NB: user home directory is set at Z:\
rem    Use: Users.bat, LogonName, LastName, FirstName   
rem       
net use u: /delete
Net use u: \\ServerName\ShareName
u:
PAUSE
REM for /f %%v in (u:\user.txt) do net user %%v P@ssword /add /fullname:%%v

for /f "eol=; tokens=1,2,3,4 delims=," %%v in (u:\user.txt) do net user %%v P@ssword /add /fullname:"%%w"
PAUSE
for /f "eol=; tokens=1,2,3,4 delims=," %%v in (u:\user.txt) do net user %%v /Comment:"enter comment here" /scriptpath:LogonScript1.bat
PAUSE
REM for /f %%v in (u:\user.txt) do net user %%v /Comment:"enter comment here" /scriptpath:LoginScript1.bat
for /f %%v in (u:\user.txt) do net group "Domain Users" %%v /add
for /f %%v in (u:\user.txt) do net group GlobalGroupName %%v /add
for /f %%v in (u:\user.txt) do net group GlobalGroupName %%v /add

PAUSE

::creates directory for each user
u:
for /f %%v in (u:\user.txt) do md u:\%%v

::Gives the user ownership to his directory
for /f %%v in (u:\user.txt) do subinacl /subdirectory u:\%%v /setowner=%%v /grant=%%v=F

::Creates a remote hidden share and Gives Change permissions to the user

for /f %%v in (u:\User.txt) do net share %%v=d:\users\SubDirectory\%%v /grant:%%v,CHANGE

REM if you need to delete shares perform the following command
REM for /f %%v in (u:\user.txt) do net share \\ServerName\%%v /DELETE

PAUSE

Published: 8/10/2005 9:03 PM

Troubleshooting NetBIOS Name Resolution Problems

Use NbtStat to verify that you have the right IP address for a specific NetBIOS name is to use a tool that displays protocol statistics and TCP/IP connections using NBT (NetBIOS over TCP/IP). The syntax is case sensitive. For example, nbtstat -A lists the remote computer name table when given its IP address, and nbtstat -a lists the remote computer name table when given its name.

Examples of NetBIOS name resolution problems:

  1. You can ping another computer, however Nbtstat believes it is a computer other than the one that you specified. This means that there is a problem with name to address mapping. (An Nbtstat result overrules a Ping result.)
  2. You cannot ping another computer, and you receive a "Bad IP Address" error. This means that the name cannot be found.
  3. You cannot ping and you receive a "Request timed out" error. This means that either there are name resolution or connectivity problems or that the server is not functioning.
Using Nslookup for Name Resolution

You can use Nslookup to perform DNS queries and to examine the contents of zone files on local and remote servers.  To use Nslookup in interactive mode and to verify name resolution, at the command prompt, type the following:  NSLOOKUP

Published: 8/4/2008 9:01 PM

Troubleshooting DCdiag

This is continuing my entries on troubleshooting.  Use DCdiag to perform a fully automatic analysis with little intervention. It is a read-only tool that does not affect the state of the object. Although it allows specific tests to be run individually, it is not intended as a general toolbox of commands to perform specific tasks. Best use is to run all commands at once and compare the outcome of each as some my be related.

Use the Dcdiag tool to diagnose domain controller status for the following:

  • Connectivity
  • Replication
  • Topology Integrity
  • Directory Partition Head Permissions
  • User Permissions
  • Locator Functionality
  • Inter-site Health
  • Trust Verification
  • Diagnose Replication Latencies
  • Replication of Trust Objects
  • File Replication Service
  • Critical Services Check

Published: 8/1/2008 8:57 PM

Forest to Forest Trust - Ports Required

For Active Directory to function correctly through a firewall, the Internet Control Message Protocol (ICMP) protocol must be allowed through the firewall from the clients to the domain controllers so that the clients can receive Group Policy information.  You will need the following ports opened to create the trust and to perform the user/group administration after the trust is established.

Resource Material: Microsoft KB http://support.microsoft.com/default.aspx/kb/179442/

http://technet2.microsoft.com/WindowsServer/en/library/108124dd-31b1-4c2c-9421-6adbc1ebceca1033.mspx?mfr=true

(migrated content from old site, need to relink pictures)

* NOTE: The port for WINS is optional.  It is not required for a trust but only if YOUR Active Directory configuration is dependent on WINS still for resolution.

Published: 12/1/2008 8:54 PM

Configure RPC ports from Dynamic to Limited Range

Many things require communication for RPC over ports 1024-65535/TCP.  In many cases having all of these ports open is not practical.  Microsoft recommends you reduce this number of ports. Material References:  http://support.microsoft.com/kb/154596 . 

This is nothing new, I have been doing this per Microsoft's recommendations for several years, although this referenced KB is newer, if you search you will find similar articles published since Active Directories first release.

This is a best practice for security lock down, and has been for years. I heard an engineer once say it breaks your support contract with Microsoft to make ANY edits to the registry.  That is simply incorrect, contact Microsoft to verify.  If it is to fix known reported problems where Microsoft publishes a KB article instructing you how like above, this is supported.

  1. Start - Run - Regedt32 - modify the following parameters for RPC. The RPC Port key values are all located in the following key in the registry: HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet\ Key Data Type Ports REG_MULTI_SZ
  2. If any entries are outside the range of 0 to 65535, or if any string cannot be interpreted, the RPC runtime treats the entire configuration as invalid. Select a smaller range like 25000-25500.
  3. PortsInternetAvailable REG_SZ Y or N (not case-sensitive)
    If Y, the ports listed in the Ports key are all the Internet-available ports on that computer. If N, the ports listed in the Ports key are all those ports that are not Internet-available.
  4. UseInternetPorts REG_SZ ) Y or N (not case-sensitive Specifies the system default policy.
    If Y, the processes using the default will be assigned ports from the set of Internet-available ports, as defined previously. If N, the processes using the default will be assigned ports from the set of intranet-only ports.
  5. Example:
  6. 1. Add the Internet key under: HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
  7. 2. Under the Internet key, add the values "Ports" (MULTI_SZ), "PortsInternetAvailable" (REG_SZ), and "UseInternetPorts" (REG_SZ).
  8. The new registry key appears as follows:
         Ports: REG_MULTI_SZ: 25000-25500
         PortsInternetAvailable: REG_SZ: Y
         UseInternetPorts: REG_SZ: Y 
  9. Then restart the server.

Published: 10/31/2008 8:53 PM

Domain and DNS Troubleshooting

These are some of the commands I commonly run to troubleshoot Domain and DNS problems.

Repadmin /bind

dcdiag /s:DomainControllerName /u:DomainName\Username

dcdiag /s:DomainControllerName /u:DomainName\Username /test:Connectivity

dcdiag /s:DomainControllerName /u:DomainName\Username /test:Replications

dcdiag /s:DomainControllerName /u:DomainName\Username /test:Topology

dcdiag /s:DomainControllerName /u:DomainName\Username /test:NetLogons

dcdiag /s:DomainControllerName /u:DomainName\Username /test:KnowsOfRoleHolders

dcdiag /s:DomainControllerName /u:DomainName\Username /test:FsmoCheck

dcdiag /s:DomainControllerName /u:DomainName\Username /test:kccevent

dcdiag /s:DomainControllerName /u:DomainName\Username /test:DcPromo

              /DnsDomain:DomainDNSName /ChildDomain

dcdiag /s:DomainControllerName /u:DomainName\Username /test:DNS

nltest /server:TargetDCname /sc_query:TargetTrustedDomain

nltest /server:TargetDCname /dcname:TargetTrustedDomain

nltest /server:TargetDCname /sim_sync:TargetDomain

Published: 3/13/2008 8:44 PM

Active Directory Authoratative Restore

Active Directory is located in the directory Winnt\Ntds .


The steps below are taken from a Microsoft white paper or manual. I apologize but I have lost the link to the document, but it is not my own but a Microsoft doc. This is here more for my reference.

An Authoritative Restore occurs after nonauthoritative restore has been performed. During authoritative restore, an entire directory, a subtree, or individual objects can be designated to take precedence over any other instances of those objects on domain controllers. So, through normal replication, the restored domain controller becomes authoritative in relation to its replication partners. Authoritative restore is typically used to restore a system to a previously known state, for example before Active Directory objects were erroneously deleted. The

To restore system state data

1. Start Backup.
2. Click the Restore tab, and then select the check box for any drive, folder, or file that you want to restore.
3. Click the box next to System State to restore the system state data along with any other data you have selected for the current restore operation.
Caution: If you restore the system state data, and you do not designate an alternate location for the restored data, Backup erases the system state data that is currently on your computer and replaces it with the system state data you are restoring.

When you back up the system state data, a copy of your registry files is also saved in %SystemRoot%\Repair\Regback.

Ntdsutil command-line tool allows you to authoritatively restore the entire directory, a subtree, or individual objects provided they are leaf objects.

Performing an Authoritative Restore

When a domain contains more than one domain controller, Active Directory replicates directory objects, such as users, groups, organizational units, and computers, to all the domain controllers in that domain.

When you are restoring a domain controller by using backup and restore programs, such as Ntbackup or those from third-party providers, the default mode for the restore is nonauthoritative. This means that the restored server is brought up-to-date with its replicas through the normal replication mechanism. For example, if a domain controller is restored from a backup tape that is two weeks old, when you restart it, the normal replication mechanism brings it up-to-date with respect to its replication partners.

Authoritative restore allows the administrator to recover a domain controller, restore it to a specific point in time, and mark objects in Active Directory as being authoritative with respect to their replication partners. For example, you might need to perform an authoritative restore if an administrator inadvertently deletes an organizational unit containing a large number of users. If you restore the server from tape, the normal replication process would not restore the inadvertently deleted organizational unit. Authoritative restore allows you to mark the organizational unit as authoritative and force the replication process to restore it to all of the other domain controllers in the domain.

Authoritative Restore Commands

Restore database

Marks the entire Ntds.dit (both the domain and configuration naming contexts held by the domain controller) as authoritative. The schema cannot be authoritatively restored.

Restore database verinc %d

Marks the entire Ntds.dit (both the domain and configuration naming contexts held by the domain controller) as authoritative and increments the version number by %d. Use this option only to authoritatively restore over a previous, incorrect, authoritative restore, such as an authoritative restore from a backup that contains the problem you want to restore over.

Restore subtree %s

Marks subtree (and all children of subtree) as being authoritative. The subtree is defined by using the fully distinguished name of the object.

Restore subtree %s verinc %d

Marks subtree (and all children of subtree) as being authoritative and increments the version number by %d. The subtree is defined by using the fully distinguished name of the object. Use this option only to authoritatively restore over a previous, incorrect, authoritative restore, such as an authoritative restore from a backup that contains the problem you want to restore over.

Originally Published: 11/30/2008 8:29 PM