Entra ID (AD)

Technical articles about authentication and authorization of directory services for Azure cloud. Articles include topics such as domain controllers, DNS, Group Policy Management, certifictates, and single sign on. Learn about using Active Directory Management Tools and PowerShell.

What’s the deal with Kerb3961?

Howdy, everyone! I wanted to write this blog post to discuss the new Kerb3961 library introduced in Windows Server 2025 / Windows 11 24H2. It is (hopefully) making encryption type (etype) usage within Kerberos much easier to anticipate and understand. Let’s start with… Kerb3961, named after RFC3961, is a refactor of the Kerberos cryptography engine […]

What’s the deal with Kerb3961? Continue Reading

Lost access to your Root CA in your 2-Tier PKI? Don’t worry, Use Cross Signing to Recover!

Hello, this is Byron from the Microsoft Directory Services Support team. Today, I’d like to share information about an alternative recovery approach for Public Key Infrastructure (PKI) environments. Consider a scenario where the Root Certification Authority (CA) is permanently lost—for example, due to accidental deletion of the Root CA virtual machine, or the system entering

Lost access to your Root CA in your 2-Tier PKI? Don’t worry, Use Cross Signing to Recover! Continue Reading

Stop Worrying and Love the Outage, Vol III: Cached Logons

This is the third article in a series:Stop Worrying and Love the Outage, Vol I: Group Policy and Sharing ViolationsStop Worrying and Love the Outage, Vol II: DCs, custom ports, and Firewalls/ACLsStop Worrying and Love the Outage, Vol III: Cached LogonsStop Worrying and Love the Outage, Vol IV: Preference items | Microsoft Community Hub  

Stop Worrying and Love the Outage, Vol III: Cached Logons Continue Reading

Stop Worrying and Love the Outage, Vol II: DCs, custom ports, and Firewalls/ACLs

This is the second article in a series: Stop Worrying and Love the Outage, Vol I: Group Policy and Sharing ViolationsStop Worrying and Love the Outage, Vol II: DCs, custom ports, and Firewalls/ACLs Stop Worrying and Love the Outage, Vol III: Cached LogonsStop Worrying and Love the Outage, Vol IV: Preference items Hello, it’s Chris

Stop Worrying and Love the Outage, Vol II: DCs, custom ports, and Firewalls/ACLs Continue Reading

Stop Worrying and Love the Outage, Vol IV: Preference items

Note: We apologize for the current viewing experience of these blogs on non-mobile devices.  We are working to resolve this issue as soon as possible.  This is the fourth article in a series:Stop Worrying and Love the Outage, Vol I: Group Policy and Sharing ViolationsStop Worrying and Love the Outage, Vol II: DCs, custom ports,

Stop Worrying and Love the Outage, Vol IV: Preference items Continue Reading

Synchronizing Time on Virtualized AD DS Environments – VMICTimeProvider vs AD

 Hey everyone!  Allan Sandoval from the Directory Services team here.  We’ve all experienced a lot of changes since the rise of cloud computing and virtualization, and our time synchronization technology (Windows Time) is no exception.  Today, I want to shed light on the VMICTimeProvider and its impact on Virtual Machines (VM) within an Active Directory

Synchronizing Time on Virtualized AD DS Environments – VMICTimeProvider vs AD Continue Reading

Windows Scoping: The Secret Sauce to Squashing Windows Gremlins Faster!

Hello everyone, this is Tagore Nadh, a Sr. Technical Advisor on the Directory Services support team in Microsoft.   In this article, I will explain why scoping is important with a couple of good examples. Generic Scoping Questions: What is your objective and the reason behind it? Can you provide a detailed description of the issue?

Windows Scoping: The Secret Sauce to Squashing Windows Gremlins Faster! Continue Reading

Secure Time Seeding on DCs: A Note from the Field

        Hello all, Chris from Directory Services here again.  Lately, we’ve seen an increase in cases where DCs (Domain Controllers) suffer issues with time jumps, many times into the future.   As everyone here knows, time synchronization is critical for Active Directory and other applications.  As time has passed (hyuk hyuk), we’ve seen some interesting scenarios from

Secure Time Seeding on DCs: A Note from the Field Continue Reading

Remote Desktop Services enrolling for TLS certificate from an Enterprise CA

Hey! Rob Greene again.  Been on a roll with all things crypto as of late, and you are not going to be disappointed with this one either! Background Many know that Remote Desktop Services uses a self-signed certificate for its TLS connection from the RDS Client to the RDS Server over the TCP 3389 connection

Remote Desktop Services enrolling for TLS certificate from an Enterprise CA Continue Reading