Skip to content

Commit 541666b

Browse files
authored
Merge pull request MicrosoftDocs#2317 from damabe/damabe-Validation1
Message fixes | Validation issues | 1 (BULK)
2 parents 299e46c + d7916f3 commit 541666b

56 files changed

Lines changed: 6304 additions & 6302 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎WindowsServerDocs/identity/ad-ds/active-directory-functional-levels.md‎

Lines changed: 224 additions & 224 deletions
Large diffs are not rendered by default.

‎WindowsServerDocs/identity/ad-ds/deploy/Install-Active-Directory-Domain-Services--Level-100-.md‎

Lines changed: 533 additions & 533 deletions
Large diffs are not rendered by default.

‎WindowsServerDocs/identity/ad-ds/deploy/RODC/Forest-Wide-Updates.md‎

Lines changed: 98 additions & 98 deletions
Large diffs are not rendered by default.

‎WindowsServerDocs/identity/ad-ds/deploy/Troubleshooting-Domain-Controller-Deployment.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ The built-in logs are the most important instrument for troubleshooting issues w
2727
|--|--|
2828
| Server Manager or ADDSDeployment Windows PowerShell operations | - %systemroot%\debug\dcpromoui.log<p>- %systemroot%\debug\dcpromoui*.log |
2929
| Installation/Promotion of the domain controller | - %systemroot%\debug\dcpromo.log<p>- %systemroot%\debug\dcpromo*.log<p>- Event viewer\Windows logs\System<p>- Event viewer\Windows logs\Application<p>- Event viewer\Applications and services logs\Directory Service<p>- Event viewer\Applications and services logs\File Replication Service<p>- Event viewer\Applications and services logs\DFS Replication |
30-
| Forest or domain upgrade | - %systemroot%\debug\adprep\\<datetime>\adprep.log<p>- %systemroot%\debug\adprep\\<datetime>\csv.log<p>- %systemroot%\debug\adprep\\<datetime>\dspecup.log<p>- %systemroot%\debug\adprep\\<datetime>\ldif.log* |
30+
| Forest or domain upgrade | - %systemroot%\debug\adprep&#92;\<datetime>\adprep.log<p>- %systemroot%\debug\adprep&#92;\<datetime>\csv.log<p>- %systemroot%\debug\adprep&#92;\<datetime>\dspecup.log<p>- %systemroot%\debug\adprep&#92;\<datetime>\ldif.log* |
3131
| Server Manager ADDSDeployment Windows PowerShell deployment engine | - Event viewer\Applications and services logs\Microsoft\Windows\DirectoryServices-Deployment\Operational |
3232
| Windows Servicing | - %systemroot%\Logs\CBS\\*<p>- %systemroot%\servicing\sessions\sessions.xml<p>- %systemroot%\winsxs\poqexec.log<p>- %systemroot%\winsxs\pending.xml |
3333

@@ -288,7 +288,7 @@ The following are common issues seen during the Windows Server 2012 development
288288

289289
| Issue | Prerequisite adprep check fails with error "Unable to perform Exchange schema conflict check" |
290290
|--|--|
291-
| Symptoms | When attempting to promote a Windows Server 2012 domain controller into an existing Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2 forest, prerequisite check fails with error:<p>Code - Verification of prerequisites for AD prep failed. Unable to perform Exchange schema conflict check for domain *<domain name>* (Exception: the RPC server is unavailable)<p>The adprep.log shows error:<p>Code - Adprep could not retrieve data from the server *<domain controller>*<p>through Windows Management Instrumentation (WMI). |
291+
| Symptoms | When attempting to promote a Windows Server 2012 domain controller into an existing Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2 forest, prerequisite check fails with error:<p>Code - Verification of prerequisites for AD prep failed. Unable to perform Exchange schema conflict check for domain *\<domain name>* (Exception: the RPC server is unavailable)<p>The adprep.log shows error:<p>Code - Adprep could not retrieve data from the server *\<domain controller>*<p>through Windows Management Instrumentation (WMI). |
292292
| Resolution and Notes | The new domain controller cannot access WMI through DCOM/RPC protocols against the existing domain controllers. To date, there have been three causes for this:<p>- A firewall rule blocks access to the existing domain controllers<p>- The NETWORK SERVICE account is missing from the "Logon as a service" (SeServiceLogonRight) privilege on the existing domain controllers<p>- NTLM is disabled on domain controllers, using security policies described in [Introducing the Restriction of NTLM Authentication](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd560653(v=ws.10)) |
293293

294294
| Issue | Creating a new AD DS forest always shows DNS warning |

‎WindowsServerDocs/identity/ad-ds/get-started/adac/Advanced-AD-DS-Management-Using-Active-Directory-Administrative-Center--Level-200-.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -442,7 +442,7 @@ The errors shown when no Active Directory Web Services instances are available a
442442
|Error|Operation|
443443
| --- | --- |
444444
|"Cannot connect to any domain. Refresh or try again when connection is available"|Shown at start of the Active Directory Administrative Center application|
445-
|"Cannot find an available server in the *<NetBIOS domain name>* domain that is running the Active Directory Web Service (ADWS)"|Shown when trying to select a domain node in the Active Directory Administrative Center application|
445+
|"Cannot find an available server in the *\<NetBIOS domain name>* domain that is running the Active Directory Web Service (ADWS)"|Shown when trying to select a domain node in the Active Directory Administrative Center application|
446446

447447
To troubleshoot this issue, use these steps:
448448

‎WindowsServerDocs/identity/ad-ds/get-started/replication/Active-Directory-Replication-Concepts.md‎

Lines changed: 112 additions & 112 deletions
Large diffs are not rendered by default.

‎WindowsServerDocs/identity/ad-ds/get-started/virtual-dc/Virtualized-Domain-Controller-Architecture.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ The following steps explain the process in more detail:
119119

120120
22. The guest re-enables DNS client registration now that the computer is uniquely named and networked.
121121

122-
23. The guest runs the SYSPREP modules specified by the DefaultDCCloneAllowList.xml <SysprepInformation> element in order to scrub out references to the previous computer name and SID.
122+
23. The guest runs the SYSPREP modules specified by the DefaultDCCloneAllowList.xml \<SysprepInformation> element in order to scrub out references to the previous computer name and SID.
123123

124124
24. Cloning promotion is complete.
125125

@@ -185,7 +185,7 @@ After the guest employs virtualization safeguards, NTDS replicates Active Direct
185185

186186
- If using FRS, the guest stops the NTFRS service and sets D2 BURFLAGS registry value. It then starts the NTFRS service, which non-authoritatively replicates inbound, re-using existing unchanged SYSVOL data when possible.
187187

188-
- If using DFSR, the guest stops the DFSR service and deletes the DFSR database files (default location: %systemroot%\system volume information\dfsr\\*<database GUID>*). It then starts the DFSR service, which non-authoritatively replicates inbound, re-using existing unchanged SYSVOL data when possible.
188+
- If using DFSR, the guest stops the DFSR service and deletes the DFSR database files (default location: %systemroot%\system volume information\dfsr&#92;*\<database GUID>*). It then starts the DFSR service, which non-authoritatively replicates inbound, re-using existing unchanged SYSVOL data when possible.
189189

190190
> [!NOTE]
191191
> - If the hypervisor does not provide a VM-Generation ID for comparison, the hypervisor does not support virtualization safeguards and the guest will operate like a virtualized domain controller that runs Windows Server 2008 R2 or earlier. The guest implements USN rollback quarantine protection if there is an attempt to start replicating with USNs that have not advanced past the last highest USN seen by the partner DC. For more information about USN rollback quarantine protection, see [USN and USN Rollback](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd363553(v=ws.10))

‎WindowsServerDocs/identity/ad-ds/get-started/virtual-dc/Virtualized-Domain-Controller-Deployment-and-Configuration.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -260,7 +260,7 @@ You run the cmdlet on the proposed source domain controller that you intend to c
260260

261261
|**ActiveDirectory**<p>**Cmdlet**|**Arguments**|**Explanation**|
262262
|--|--|--|
263-
|**New-ADDCCloneConfigFile**|*<no argument specified>*|Creates a blank DcCloneConfig.xml file in the DSA Working Directory (default: %systemroot%\ntds)|
263+
|**New-ADDCCloneConfigFile**|*\<no argument specified>*|Creates a blank DcCloneConfig.xml file in the DSA Working Directory (default: %systemroot%\ntds)|
264264
||-CloneComputerName|Specifies the clone DC computer name. String data type.|
265265
||-Path|Specifies the folder to create the DcCloneConfig.xml. If not specified, writes to the DSA Working Directory (default: %systemroot%\ntds). String data type.|
266266
||-SiteName|Specifies the AD logical site name to join during cloned computer account creation. String data type.|

‎WindowsServerDocs/identity/ad-ds/get-started/virtual-dc/virtualized-domain-controllers-hyper-v.md‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -88,11 +88,11 @@ Lightweight Directory Access Protocol (LDAP) tests were run on a physical domain
8888

8989
<table>
9090
<colgroup>
91-
<col style="width: 20%" />
92-
<col style="width: 20%" />
93-
<col style="width: 20%" />
94-
<col style="width: 20%" />
95-
<col style="width: 20%" />
91+
<col>
92+
<col>
93+
<col>
94+
<col>
95+
<col>
9696
</colgroup>
9797
<thead>
9898
<tr class="header">
Lines changed: 71 additions & 71 deletions
Original file line numberDiff line numberDiff line change
@@ -1,71 +1,71 @@
1-
---
2-
description: "Learn more about: AD Forest Recovery - Raising the value of available RID pools"
3-
title: AD Forest Recovery - Raising RID pools
4-
ms.author: daveba
5-
author: iainfoulds
6-
manager: daveba
7-
ms.date: 08/09/2018
8-
ms.topic: article
9-
ms.assetid: c37bc129-a5e0-4219-9ba7-b4cf3a9fc9a4
10-
---
11-
# AD Forest Recovery - Raising the value of available RID pools
12-
13-
>Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 and 2012 R2, Windows Server 2008 and 2008 R2
14-
15-
Use the following procedure to raise the value of the relative ID (RID) pools that the RID operations master will allocate after that DC is restored. By raising the value of the available RID pools, you can ensure that no DC allocates a RID for a security principal that was created after the backup that was used to restore the domain.
16-
17-
## About Active Directory RID Pools and rIDAvailablePool
18-
19-
Each domain has an object **CN=RID Manager$,CN=System,DC**=<*domain_name*>. This object has an attribute named **rIDAvailablePool**. This attribute value maintains the global RID space for an entire domain. The value is a large integer with upper and lower parts. The upper part defines the number of security principals that can be allocated for each domain (0x3FFFFFFF or just over 1 billion). The lower part is the number of RIDs that have been allocated in the domain.
20-
21-
> [!NOTE]
22-
> In Windows Server 2016 and 2012, the number of security principals that can be allocated is increased to just over 2 billion. For more information, see [Managing RID issuance](./managing-rid-issuance.md).
23-
24-
- Sample Value: 4611686014132422708
25-
- Low Part: 2100 (beginning of the next RID pool to be allocated)
26-
- Upper Part: 1073741823 (total number of RIDs that can be created in a domain)
27-
28-
When you increase the value of the large integer, you increase the value of the low part. For example, if you add 100,000 to the sample value of 4611686014132422708 for a sum of 4611686014132522708, the new low part is 102100. This indicates that the next RID pool that will be allocated by the RID master will begin with 102100 instead of 2100.
29-
30-
### To raise the value of available RID pools using adsiedit and the calculator
31-
32-
1. Open Server Manager, click **Tools** and click **ADSI Edit**.
33-
2. Right-click, select **Connect to** and connect do the Default Naming Context and click **OK**.
34-
![Screenshot that shows how to connect to the Default Naming Context](media/AD-Forest-Recovery-Raise-RID-Pool/adsi1.png)
35-
3. Browse to the following distinguished name path: **CN=RID Manager$,CN=System,DC=<domain name>**.
36-
![Screenshot that shows how to browse to the distinguished name path.](media/AD-Forest-Recovery-Raise-RID-Pool/adsi2.png)
37-
3. Right-click and select the properties of CN=RID Manager$.
38-
4. Select the attribute **rIDAvailablePool**, click **Edit**, and then copy the large integer value to the clipboard.
39-
![Screenshot that shows the selected rIDAvailablePool attribute.](media/AD-Forest-Recovery-Raise-RID-Pool/adsi3.png)
40-
5. Start calculator, and from the **View** menu, select **Scientific Mode**.
41-
6. Add 100,000 to the current value.
42-
![Screenshot that shows where to add 100,000 to the current value.](media/AD-Forest-Recovery-Raise-RID-Pool/adsi4.png)
43-
7. Using ctrl-c, or the **Copy** command from the **Edit** menu, copy the value to the clipboard.
44-
8. In the edit dialog of adsiedit, paste this new value.
45-
![ADSI Edit](media/AD-Forest-Recovery-Raise-RID-Pool/adsi5.png)
46-
9. Click **OK** in the dialog, and **Apply** in the property sheet to update the **rIDAvailablePool** attribute.
47-
48-
### To raise the value of available RID pools using LDP
49-
50-
1. At the command prompt, type the following command, and then press ENTER:
51-
**ldp**
52-
2. Click **Connection**, click **Connect**, type the name of RID manager, and then click **OK**.
53-
![Screenshot that shows where to type the name of the RID manager.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp1.png)
54-
3. Click **Connection**, click **Bind**, select **Bind with credentials** and type your administrative credentials, and then click **OK**.
55-
![Screenshot that shows the Bind with credentials option.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp2.png)
56-
4. Click **View**, click **Tree** and then type the following distinguished name path: CN=RID Manager$,CN=System,DC=*domain name*
57-
![Screenshot that shows where you type the distinguished name path.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp3.png)
58-
5. Click **Browse**, and then click **Modify**.
59-
6. Add 100,000 to the current **rIDAvailablePool** value, and then type the sum into **Values**.
60-
7. In **Dn**, type `cn=RID Manager$,cn=System,dc=`*<domain name\>*.
61-
8. In **Edit Entry Attribute**, type `rIDAvailablePool`.
62-
9. Select **Replace** as the operation, and then click **Enter**.
63-
![Screenshot that shows the Replace option.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp4.png)
64-
10. Click **Run** to run the operation. Click **Close**.
65-
11. To validate the change, click **View**, click **Tree**, and then type the following distinguished name path: CN=RID Manager$,CN=System,DC=*domain name*. Check the **rIDAvailablePool** attribute.
66-
![LDP](media/AD-Forest-Recovery-Raise-RID-Pool/ldp5.png)
67-
68-
## Next Steps
69-
70-
- [AD Forest Recovery Guide](AD-Forest-Recovery-Guide.md)
71-
- [AD Forest Recovery - Procedures](AD-Forest-Recovery-Procedures.md)
1+
---
2+
description: "Learn more about: AD Forest Recovery - Raising the value of available RID pools"
3+
title: AD Forest Recovery - Raising RID pools
4+
ms.author: daveba
5+
author: iainfoulds
6+
manager: daveba
7+
ms.date: 08/09/2018
8+
ms.topic: article
9+
ms.assetid: c37bc129-a5e0-4219-9ba7-b4cf3a9fc9a4
10+
---
11+
# AD Forest Recovery - Raising the value of available RID pools
12+
13+
>Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 and 2012 R2, Windows Server 2008 and 2008 R2
14+
15+
Use the following procedure to raise the value of the relative ID (RID) pools that the RID operations master will allocate after that DC is restored. By raising the value of the available RID pools, you can ensure that no DC allocates a RID for a security principal that was created after the backup that was used to restore the domain.
16+
17+
## About Active Directory RID Pools and rIDAvailablePool
18+
19+
Each domain has an object **CN=RID Manager$,CN=System,DC**=<*domain_name*>. This object has an attribute named **rIDAvailablePool**. This attribute value maintains the global RID space for an entire domain. The value is a large integer with upper and lower parts. The upper part defines the number of security principals that can be allocated for each domain (0x3FFFFFFF or just over 1 billion). The lower part is the number of RIDs that have been allocated in the domain.
20+
21+
> [!NOTE]
22+
> In Windows Server 2016 and 2012, the number of security principals that can be allocated is increased to just over 2 billion. For more information, see [Managing RID issuance](./managing-rid-issuance.md).
23+
24+
- Sample Value: 4611686014132422708
25+
- Low Part: 2100 (beginning of the next RID pool to be allocated)
26+
- Upper Part: 1073741823 (total number of RIDs that can be created in a domain)
27+
28+
When you increase the value of the large integer, you increase the value of the low part. For example, if you add 100,000 to the sample value of 4611686014132422708 for a sum of 4611686014132522708, the new low part is 102100. This indicates that the next RID pool that will be allocated by the RID master will begin with 102100 instead of 2100.
29+
30+
### To raise the value of available RID pools using adsiedit and the calculator
31+
32+
1. Open Server Manager, click **Tools** and click **ADSI Edit**.
33+
2. Right-click, select **Connect to** and connect do the Default Naming Context and click **OK**.
34+
![Screenshot that shows how to connect to the Default Naming Context](media/AD-Forest-Recovery-Raise-RID-Pool/adsi1.png)
35+
3. Browse to the following distinguished name path: **CN=RID Manager$,CN=System,DC=\<domain name>**.
36+
![Screenshot that shows how to browse to the distinguished name path.](media/AD-Forest-Recovery-Raise-RID-Pool/adsi2.png)
37+
3. Right-click and select the properties of CN=RID Manager$.
38+
4. Select the attribute **rIDAvailablePool**, click **Edit**, and then copy the large integer value to the clipboard.
39+
![Screenshot that shows the selected rIDAvailablePool attribute.](media/AD-Forest-Recovery-Raise-RID-Pool/adsi3.png)
40+
5. Start calculator, and from the **View** menu, select **Scientific Mode**.
41+
6. Add 100,000 to the current value.
42+
![Screenshot that shows where to add 100,000 to the current value.](media/AD-Forest-Recovery-Raise-RID-Pool/adsi4.png)
43+
7. Using ctrl-c, or the **Copy** command from the **Edit** menu, copy the value to the clipboard.
44+
8. In the edit dialog of adsiedit, paste this new value.
45+
![ADSI Edit](media/AD-Forest-Recovery-Raise-RID-Pool/adsi5.png)
46+
9. Click **OK** in the dialog, and **Apply** in the property sheet to update the **rIDAvailablePool** attribute.
47+
48+
### To raise the value of available RID pools using LDP
49+
50+
1. At the command prompt, type the following command, and then press ENTER:
51+
**ldp**
52+
2. Click **Connection**, click **Connect**, type the name of RID manager, and then click **OK**.
53+
![Screenshot that shows where to type the name of the RID manager.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp1.png)
54+
3. Click **Connection**, click **Bind**, select **Bind with credentials** and type your administrative credentials, and then click **OK**.
55+
![Screenshot that shows the Bind with credentials option.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp2.png)
56+
4. Click **View**, click **Tree** and then type the following distinguished name path: CN=RID Manager$,CN=System,DC=*domain name*
57+
![Screenshot that shows where you type the distinguished name path.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp3.png)
58+
5. Click **Browse**, and then click **Modify**.
59+
6. Add 100,000 to the current **rIDAvailablePool** value, and then type the sum into **Values**.
60+
7. In **Dn**, type `cn=RID Manager$,cn=System,dc=`*<domain name\>*.
61+
8. In **Edit Entry Attribute**, type `rIDAvailablePool`.
62+
9. Select **Replace** as the operation, and then click **Enter**.
63+
![Screenshot that shows the Replace option.](media/AD-Forest-Recovery-Raise-RID-Pool/ldp4.png)
64+
10. Click **Run** to run the operation. Click **Close**.
65+
11. To validate the change, click **View**, click **Tree**, and then type the following distinguished name path: CN=RID Manager$,CN=System,DC=*domain name*. Check the **rIDAvailablePool** attribute.
66+
![LDP](media/AD-Forest-Recovery-Raise-RID-Pool/ldp5.png)
67+
68+
## Next Steps
69+
70+
- [AD Forest Recovery Guide](AD-Forest-Recovery-Guide.md)
71+
- [AD Forest Recovery - Procedures](AD-Forest-Recovery-Procedures.md)

0 commit comments

Comments
 (0)