1,924 questions with Windows for business | Windows Server | Devices and deployment | Configure application groups tags

Sort by: Updated
2 answers

Protected Users AD security group issue with remote server access using the IP address or alias name?

After adding to the Protected Users AD group, I am unable to access the remote server using the IP address or alias name. Protected Users Security Group | Microsoft Learn Guidance about how to configure protected accounts | Microsoft Learn Now people…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2024-09-30T11:19:53.7666667+00:00
EnterpriseArchitect 6,166 Reputation points
edited an answer 2025-08-28T07:09:42.9833333+00:00
2 answers

AD assessment tools

Are there any recommended reporting tools that you can use to scan your Active Directory setup and configuration and get a report of problems/risks/non recommended settings to address?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2024-05-20T09:11:49.9433333+00:00
crib bar 846 Reputation points
answered 2025-08-27T15:22:02.7166667+00:00
Andrew Fitzgerald 1 Reputation point
4 answers One of the answers was accepted by the question author.

The benefits in setting 'Password expiration policy' to 'Set passwords to never expire (recommended)'?

What will be the safeguard or the additional safety control we must deploy when setting the user password never to expired? Because I have seen multiple recommendations from the below sources advising to set the password to never expired. CISA:…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Server | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Entra | Other
asked 2025-02-06T13:01:28.3566667+00:00
EnterpriseArchitect 6,166 Reputation points
answered 2025-08-26T11:25:32.4533333+00:00
Jeremiah Markus 0 Reputation points
14 answers One of the answers was accepted by the question author.

Anywhere Access certificate will expire soon - I can't renew it.

Hi. I have a Windows Server 2012r2 that has had Anywhere Access for years. I've recently been getting a warning that "The Anywhere Access certificate will expire soon. You must renew the certificate to continue using Anywhere Access." I…

Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2021-06-05T15:13:32.6+00:00
Chuck Coleman 106 Reputation points
commented 2025-08-21T17:55:16.8466667+00:00
Jacob Carstens 0 Reputation points
1 answer

The local administrator account is disabled when on-premises LAPS is decommissioned and the device is moved to Intune as co-managed, without a corresponding Windows LAPS policy being applied for the same local account

Hi All, I have an on-premises legacy LAPS server managing local administrator passwords for end-user machines. As part of our modernization efforts, I’ve configured Windows LAPS in Intune and transitioned the end-user devices to a co-managed state. After…

Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2025-07-07T06:29:29.3433333+00:00
Swarnendu Das 0 Reputation points
edited a comment 2025-08-14T09:47:58.7733333+00:00
Swarnendu Das 0 Reputation points
2 answers One of the answers was accepted by the question author.

Using gMSA for replacing the Task Scheduler service account?

What steps should I follow to change the current Task Scheduler service account from using the regular AD Account in the format of CORP\service.account to a gMSA? When I try to change it manually by double-clicking on the task, it prompts for the…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2024-07-17T07:06:45.8466667+00:00
EnterpriseArchitect 6,166 Reputation points
commented 2025-08-11T20:56:57.9033333+00:00
John Curtiss 71 Reputation points
1 answer

How to configure Windows 11 as a local NTP server (works in Windows 10, not in 11)

Hello, I'm trying to configure my Windows 11 Pro machine to act as a local NTP server on my LAN. I followed the same procedure that works perfectly on Windows 10, including: Modifying the…

Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2025-07-20T08:40:12.3766667+00:00
AlexBo 0 Reputation points
answered 2025-08-08T07:16:56.4+00:00
Oliver Nguyen 450 Reputation points Independent Advisor
1 answer One of the answers was accepted by the question author.

Security requirements to be considered for Microsoft Data Migration

What specific security requirements should be considered in case of Microsoft O365 and Azure Data Migration between tenants. Is there any specific checklist from Microsoft which can be considered as an initial starting point? Thanks. Regards.

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Intune | Security
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2024-06-01T10:52:30.39+00:00
REDONDO Maria-Luisa (HORSE) 40 Reputation points
commented 2025-07-25T18:23:49.0433333+00:00
socorro jimenez 0 Reputation points
1 answer

Outlook 2024 slows down massively when using remote credential guard

I would like to share some information here that might save one or the other admin who is in charge of Office and/or network security a few gray hairs. Also, I hope some MS office developers read this and ask themselves how this is possible and fix…

Exchange | Exchange Server | Other
Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2025-01-10T10:54:21.4166667+00:00
MTG 1,251 Reputation points
commented 2025-07-25T08:01:09.02+00:00
MTG 1,251 Reputation points
2 answers

Microsoft XDR (Defender) - DeviceEvents - ShellLinkCreateFileEvent

Hi everyone, I've been trying to create a hunting query in the Defender portal to identify when a malicious .lnk file is created. I noticed that an interesting event to detect and analyze this is "DeviceEvents --> ShellLinkCreateFileEvent",…

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2024-12-19T18:02:05.2466667+00:00
viri4to 10 Reputation points
commented 2025-07-18T10:16:55.7533333+00:00
viri4to 10 Reputation points
3 answers One of the answers was accepted by the question author.

Windows Server 2022 - Update Error 0x80073701 for KB5005619

Good day all I have updated several servers from 2019 to 2022, which worked without any problems. But on one server, the message appears in the updates: "There were some issues installing the updates, but we will try again later". If you…

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2021-10-04T08:13:50.643+00:00
MisterDeeds 126 Reputation points
commented 2025-07-07T20:58:04.5433333+00:00
Daniel Kaliel 1,356 Reputation points
1 answer

Adding Authority Key Identifier (OID: 2.5.29.35) to CAPolicy.inf in ADCS

The goal is to configure a new Certificate Authority (CA) using Active Directory Certificate Services (ADCS) and add the Authority Key Identifier (AKI) extension to the root certificate generated during CA installation. The AKI needs to match the Subject…

Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2025-06-27T10:02:52.45+00:00
Vinay Thakur 0 Reputation points
answered 2025-07-02T06:27:27.3666667+00:00
Chen Tran 1,805 Reputation points Independent Advisor
9 answers One of the answers was accepted by the question author.

CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability

Hi All https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900 To remediate the vulnerability CVE-2013-3900 is to add the below registry values. [HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config] …

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2023-02-20T20:35:49.2333333+00:00
Roger Roger 7,201 Reputation points
edited a comment 2025-06-09T01:47:38.3233333+00:00
William Chung 1 Reputation point
1 answer One of the answers was accepted by the question author.

Converting Trusted Azure VMs to Standard VMs

I have created a Windows Server VM with Trusted Launch Virtual Machine and am unable to add it to Azure Site Recovery. Is there a way to convert the running VM to a standard VM? Additionally, I am unable to add backups to a standard backup policy.

Azure Backup
Azure Backup
An Azure backup service that provides built-in management at scale.
1,553 questions
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,294 questions
Azure Site Recovery
Azure Site Recovery
An Azure native disaster recovery service. Previously known as Microsoft Azure Hyper-V Recovery Manager.
845 questions
Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2023-10-02T21:54:20.85+00:00
Jagroop Kaur 20 Reputation points
commented 2025-06-02T10:28:36.0166667+00:00
SadiqhAhmed-MSFT 49,421 Reputation points Microsoft Employee Moderator
4 answers

Open ports are shown as blocked

Hello, I have a question regarding the installation of an Exchange Server 2016. Currently, I am getting error messages at testconnectivity.microsoft.com regarding closed ports: "Testing TCP port 443 on host autodiscover.DOMAIN:TLD to ensure…

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2021-01-04T21:02:13.963+00:00
Exchange-Admin 21 Reputation points
edited the question 2025-05-29T22:49:32.7866667+00:00
DillanSimmons 6 Reputation points Admin
1 answer One of the answers was accepted by the question author.

Microsoft Defender Antivirus Vs Symantec Endpoint Protection

Hi, We are looking into replace Symantec Endpoint Protection with Microsoft Defender and have some questions. Our environment is as follow 100 servers (Windows Server 2003, 2008 R2, 2012 R2, 2016 and 2019) 100 clients (Windows 7 Ent, Windows…

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2021-01-04T10:21:37.893+00:00
andreas bright 581 Reputation points
edited the question 2025-05-29T22:49:28.7566667+00:00
DillanSimmons 6 Reputation points Admin
3 answers

Enable Bitlocker On file Server

Hi, Our Security team decides to use BitLocker encryption on file server disks, my question does it supported or not. does the user will be able to access the shared files after enables BitLocker. Thanks

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2020-12-13T10:18:50.18+00:00
Ahmed Essam 211 Reputation points
edited the question 2025-05-29T21:57:07.73+00:00
DillanSimmons 6 Reputation points Admin
1 answer One of the answers was accepted by the question author.

PKI: can a SubCA be signed by another RootCA than the original?

Hi, Can an existing Enterprise Subordinate CA be signed by a new Root CA? This SubCA will be revoked by the original Root, as it will no longer be part of the current hierarchy. Our client may want to have the SubCA continue running without having to…

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2020-12-11T10:30:13.607+00:00
KnowNothingThomas 21 Reputation points
edited the question 2025-05-29T21:56:53.6133333+00:00
DillanSimmons 6 Reputation points Admin
3 answers One of the answers was accepted by the question author.

IP is not resolving while doing nslookup

Hi I have removed DNS from my server and I have added the destination host IP in the Hosts file. After doing NSLOOUP I am getting error as IP is not resolved. Can someone please help me?

Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2020-12-11T10:20:21.5+00:00
Fahrid F 201 Reputation points
edited the question 2025-05-29T21:56:51.4933333+00:00
DillanSimmons 6 Reputation points Admin
2 answers

PowersShell Trusted Hosts Illusive Windows Server 2016 Interactions.

Hello I am having a Issue where I want to talk to my nanosever in PowerShell, however I must add in the other subnetted addresses when the DHCP changes for nanoserver and it jumps subnets so I can PSSession back into it. I have added the new sever IP…

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
asked 2020-12-10T20:00:27.14+00:00
Anonymous
edited the question 2025-05-29T21:56:32.6666667+00:00
DillanSimmons 6 Reputation points Admin