Showing posts with label Windows 2016. Show all posts
Showing posts with label Windows 2016. Show all posts

Security #Windows Server Secure Boot playbook for certificates expiring in 2026

 

Windows Server Secure Boot playbook for certificates expiring in 2026

Learn about tools and options available to organizations to update Secure Boot certificates on Windows Server. Certificates begin expiring in June 2026. You must update them before that date to help keep your security posture. Many recent platforms already include the supported 2023 certificates in firmware. However, for the ones that need to be updated, you need to manage this process manually.

 

When will this happen: 

·     The tools are already available to help you to proactively inventory, monitor, and apply updated certificates to your Windows Server devices.

·     June 2026: The 2011 Secure Boot certificate authorities (CAs) begin expiring.

 

How this will affect your organization: 

Systems on the 2011 CAs after June 2026 are at risk of running on degraded security posture. To update these systems, please be proactive and follow our recommended approach.

 

What you need to do to prepare: 

Read complete guidance in Additional information for details on how to: 

1.  Inventory and prepare your environment.  

2.  Monitor and check your devices for Secure Boot status.  

3.  Apply any needed OEM firmware updates before updating certificates.  

4.  Plan and pilot Secure Boot certificate deployments.  

5.  Troubleshoot issues. 

 

here it is an interesting article with very detailed information

https://4sysops.com/archives/update-expiring-windows-secure-boot-certificates-now/

Windows Server Secure Boot playbook for certificates expiring in 2026

Update Secure Boot certificates on Windows Server and VMs before June 2026

Microsoft #Windows Server end of support Microsoft 365 Apps on Windows Server 2016, 2019, 2022, or 2025.

TOPIC: Microsoft 365 Apps (*) end of support (a.e. Word, Excel, Outlook ...) on Windows Server 2016, 2019, 2022, or 2025.

END OF SUPPORT DEADLINES until:

  • Windows Server 2025: October 2029
  • Windows Server 2022: October 2026
  • Windows Server 2019: October 2025
    • In the interest of maintaining security while customers complete their migrations to a supported configuration, Microsoft will continue providing security updates for Microsoft 365 desktop apps running on Windows Server 2019 for a total of three years, ending on October 10, 2028.(**)
  • Windows Server 2016: October 2025
    • In the interest of maintaining security while customers complete their migrations to a supported configuration, Microsoft will continue providing security updates for Microsoft 365 desktop apps running on Windows Server 2016 for a total of three years, ending on October 10, 2028. (**)
IMPACTS:
  1. Microsoft 365 Apps (*) will not be longer supported after previous deadlines  related to O.S. versions earlier mentioned (but it does not mean that they will stop immediately to work properly ) 
  2. These deadlined will affect Virtual Desktops environments such Citrix VDA and gold image...
(*) Word, Excel, Powerpoint, Outlook for email, OneNote, OneDrive, Teams, Sharepoint

[Original articles]

Microsoft 365 Apps migration from Windows Server

(**) Windows Server end of support and Microsoft 365 Apps 



https://www.linkedin.com/pulse/microsoft-windows-server-end-support-365-apps-2016-2019-mazzanti-olgre

Server #Error 0x800f0922 installing windows update KB5066793

On microsoft Windows server at the end of installing windows update KB5066793 (at 98%) the update rolls back and shows Error 0x800f0922 in windows update.

Solution is opening regedit.exe and delete this registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{53e3d721-2aa0-4743-b2db-299d872b8e3d}

More details con be found here

https://learn.microsoft.com/en-us/answers/questions/5597589/error-0x800f0922-installing-windows-update-kb50667

Edge #How to reset profile

If you need to reset Edge settings profile (you will lose only stored password, bookmarks can be easily reimported, plugin/extentions could be re-downloaded) you need to go to this path and rename following folder

C:\Users\%username%\AppData\Local\Microsoft\Edge\User Data\

https://learn.microsoft.com/en-us/answers/questions/1355083/delete-all-microsoft-edge-profiles-(complete-reset

https://angolodiwindows.com/2022/04/come-resettare-microsoft-edge/

Server #Take action: Disable Secure Time Seeding (STS) in Windows Server 2016 and later

Microsoft recommends disabling the Secure Time Seeding (STS) in Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 due to reported timekeeping issues. Additionally, organizations should review and ensure proper time synchronization and monitoring on critical servers.   

 
When will this happen:
Microsoft recommends applying this disablement as soon as possible. This recommendation applies to all existing deployments of Windows Server 2016 and later (including domain controllers and member servers).


more details could be found here:

Security #February 2025 Deadline related KB5014754 and Certificate-based authentication changes on Windows domain controllers

Microsoft released, several months ago this important bulletin.

The key point is that, after February 2025 patch installation Windows domain controller certificate-based authentication will change (due to security reasons) to Full Enforcement mode. However, you can move back to Compatibility mode until September 2025.

There are several CA checks to be done to be sure that no problem will affect your organization.

One compatibility doubt that it might arise it could be related to organization that have no longer supported O.S. (like 2008 or older)

I think that working in compatibility mode might help to check, on internet, after February 2025 if any customer had some issues and find relative fixes/workarounds

In any case here they are essential checks that you should consider before enable “full enforcement mode”:

  1. Common Name (CN) and Subject Alternative Name (SAN): Must match the users or devices in Active Directory.
  2. Certificate Authority (CA): Certificates must be issued by a trusted and recognized CA.
  3. Certificate Chain: The certificate chain (including intermediate and root CA certificates) must be complete and valid.
  4. Revocation: It is necessary to check that the certificates have not been revoked.
  5. Time Validity: It must be verified that the certificates have not expired


KB5014754: Certificate-based authentication changes on Windows domain controllers

https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16 

https://admin.microsoft.com/AdminPortal/home?#/MessageCenter/:/messages/MC894351


MICROSOFT #LSASS high usage #after patch installation #MARCH 2024 **how to fix**

Microsoft released bullettin advising customers experiencing excessive memory consumption by LSASS on Windows Server 2012-2022 DCs that have installed the following Windows Update(s): 

KB 5035857: March 12, 2024, KB5035857 (OS Build 20348.2340) Windows Server 2022 

KB 5035849: March 12, 2024, KB5035849 (OS Build 17763.5576) Windows Server 2019 

KB 5035855: March 14, 2024, KB5035855 (OS Build 14393.5786) Windows Server 2016

KB 5035885: March 12, 2024, KB5035885 Monthly Rollup for Windows Server 2012 R2: March 12, 2024 

Fortunately, there are workable solutions that you can use to address the high LSASS usage after the 3b Windows update has been installed.

https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#march-2024

Workarounds suggested by Microsoft are related to install below fix

https://support.microsoft.com/en-us/topic/march-22-2024-kb5037422-os-build-20348-2342-out-of-band-e8f5bf56-c7cb-4051-bd5c-cc35963b18f3

[original article]

https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/this-just-in-high-lsass-usage-after-windows-update-3b-march-2024/ba-p/4096250

TEAMS #new for Virtualized Desktop Infrascructure (VDI) #deadline 30/06/2024 **no longer supported on 2016**

IMPORTANT

Microsoft announced that Classic Teams for VDI will reach end of availability on June 30th, 2024.

In case your VDI farm is on Windows Server 2016 this is no longer supported, consider previous announcement you must plan VDI migration asap.

Original article

https://learn.microsoft.com/en-us/microsoftteams/new-teams-vdi-requirements-deploy

Other important blog articles:

Teams #New Virtual Desktop Infrastructure solution #MC717969 **CITRIX**365**AZURE**

Office - Microsoft 365 Apps and operative system supported roadmap

  • Windows Server 2016: October 2025
  • Windows Server 2019: October 2025
  • Windows Server 2022: October 2026

[update 2024.06.24]

about this topic there these new dealines

https://learn.microsoft.com/en-us/microsoftteams/new-teams-vdi-requirements-deploy#requirements



Office - Microsoft 365 Apps and operative system supported roadmap

I am taking note about fact that Microsoft 365 Apps is supported on the following versions of Windows Server until the dates specified:

  • Windows Server 2016: October 2025
  • Windows Server 2019: October 2025
  • Windows Server 2022: October 2026

This news will strongly affect infrastrucures where VDI are used on previously O.S. 

https://learn.microsoft.com/en-us/deployoffice/endofsupport/windows-server-migration

Server - How to debug DNS queries on Domain Controllers

On windows Server environment, it could be useful to debug and save any DNS query submitted to your domain controllers/DNS servers.

There is an easy way to achieve this goal.

In fact you need to enable DNS debugging mode.

After this feature is enabled you can check logs and identify devices that are querying specific DNS entries/websites.

This approach it is useful, at first, about security interdipendence as well...

  1. Open DNS Manager (dnsmgmt.msc)
  2. Right-click the DNS server and click Properties.
  3. Click the Debug Logging tab.
  4. Select Log packets for debugging.
  5. Enter the File path and name, and Maximum size.


[related articles]

2016 #Multiple RDP connections #how to bypass 2 session limit

If you need to allow RDP multiple connection to windows 2016 server you can follow below procedure.

Be aware that alrerady installed internal RDS cal server is a prerequisite

Here they are minimal steps that need to be followed:

  1. Go to Server Manager in Windows Server 2016
  2. Click Add Roles and Features
  3. Then select Role-based or feature-based installation
  4. Choose:  Remote Desktop Services
  5. Then choose:  Remote Desktop Session Host
  6. Install the role
  7. restart server
  8. GDPEdit.msc
  9. Go to Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Connections
    • Set Limit number of connections to Disable.
    • Set Restrict Remote Desktop Services users to a single session to Disable.
    • Set Limit number of connections to enabled 999999
  10. Go to Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Licensing
    • Set Use the specified Remote Desktop license servers to enabled (indicate FQDN server name)
    • Set the Remote Desktop licensing mode to enabled (Per User or Per Device)
  11. gpupdate /force
  12. Test multiple RDP connections
  13. Launch RD Licensing Diagnoser snap-in to check that everything is working properly.


Windows - How to throttling Network file transfer speed

I am taking note, on blog, about an interesting article that explain several ways used to limit bandwitch usage during file transfer.

From my side, GPO, related to QoS was decisevely useful.

https://woshub.com/limit-network-file-transfer-speed-windows/

Security - Sophos AV stop definitions updates #WORKAROUND & #DETAILS **JULY 2023**

During these latter weeks Sophos released new AV version. (Core Agent 2023.1/Server Core Agent 2023.1 )

PROBLEM

  • This letter Sophos version require that these O.S. have propter September 2021 patches installed.
  • In case you are not on track with MS updates or Windows version it will occur this problem
  • End point Sophos definition updates will stop working
    • Client: Early of July 2023
    • Server: End of July 2023

AFFECTED SYSTEMS AND DEVICES

    • Windows computers:
      • From early-June 2023, Windows 10 (x64) operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Core Agent 2023.1 and above.
    • Windows servers:
      • From late-July 2023, Windows 2016 operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Server Core Agent 2023.1 and above.

  WORKAROUND APPLICABLE TO POSTPONE PROBLEM

  • The Software Packages functionality in Sophos Central can be used to assign devices to a Fixed term support (FTS) version.
  • The current version for Windows computers and servers is FTS 2022.4.3.2 and can be assigned to devices for the duration of time it takes to apply the Windows Security Updates.
  • Note: There is an expiry date for all software package versions after which devices will stop updating.
    • The expiry date for FTS 2022.4.3.2 on Windows computers is October 10, 2023.
    • The expiry date for FTS 2022.4.3.2 on Windows servers is November 14, 2023.
  • To achieve this goal you must modify Update Management policy as indicated in below screenshots.

 


APPENDIX

Full details on required updates can be found in Microsoft’s official KB5022661 on this topic. 
https://support.microsoft.com/en-gb/topic/kb5022661-windows-support-for-the-azure-code-signing-program-4b505a31-fa1e-4ea6-85dd-6630229e8ef4

In addition to having the required Windows Security Updates to verify modules signed by Azure Code Signing, devices must have the "Microsoft Identity Verification Root Certificate Authority 2020" certificate authority (CA) installed.

Generally impacted O.S. are Windows 10/11 and Windows 2016/2019/2021 server versions.

Legacy O.S. are not impacted:

Windows 8.1

  1. Windows Server 2012 R2
  2. Windows Server 2012
  3. Windows 7.0 SP1
  4. Windows Server 2008 R2
  5. Windows Server 2008 SP2 

New Installation

From the 18th of April 2023, new installations to operating systems that don't support Azure Code Signing (ACS) will fail.

Active Directory - FSMO Seizing, DRSM Password Reset and Dc health checks/best practices

As mentioned on old blog posts it is important to know which DCs (in your domain/Forest) are holding five Active directory roles using this command line.

netdom query fsmo

At the same time it is important to test your DCs health.

https://www.alessandromazzanti.com/2015/05/server-commands-to-verify-domain.html.

If you are facing unlike situation that DCs holding all 5 Ad roles (or few of them)  are no longer working you should start planning Seizing roles activity.

Here it is a Microsoft article that well apply to all Microsoft Server versions.

https://support.microsoft.com/en-sg/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control

Here they are other important suggests:
  1. Microsoft best practices suggest to have at least a Physical Domain controller indeed to have all them virtualized:
  2. I warmly suggest to check all your server and to have local Administrator password (and account enabled).
  3. To check, on all your servers/Dcs to have indicated DNS1, DNS2 and DNS3 pointing to active DCs/DNS
  4. Have 5 AD roles splitted between at least two domain controllers.
  5. About Domain controllers have DRSM Administrator password, if not known proceed to have it resetted.

[update 2026.08.27]

Powershell

Get-ADForest | Select SchemaMaster,DomainNamingMaster
Get-ADDomain | Select PDCEmulator,RIDMaster,InfrastructureMaster




Windows Server - AD cleanup/Removal DC procedure

On AD Microsoft server infrastructure it might happen that a DC death suddenly and there is any possibility to recover it (other than format/delete/wipe it)

In this specific case furthermore, you should cleanup AD metadata (to delete any referring that specific DC).

I am taking note, on blog, procedure (saving some articles that I used, in the past, to find workflow):

Metadata Cleanup Using NTDSUTIL in Windows Server 2008 R2
Clean Up Server Metadata

[Update 2022-08.02]

Scripting - File Server migration using robocopy command

In the past we managed 2008 to 2016 migration and so I am taking note about robocopy syntax that it was useful during this project. (focused on file servers migration)

Approach was replicating root folder on new server, enabling share (on new server), stopping old share folder and finally launching this command (from old file  server) for final folder synchronization.

robocopy local_drive:\localfoldername \\remote_server\remote_share_name /E /COPYALL /SEC /MIR /ZB /W:1 /R:1 /LOG:C:\locallogfolder\SYNC_OLDSERVER_VS_NEWSERVER_DATE_TIME.LOG /TEE 

/SEC it replicate security permissions

/Tee it enable video logging real time display

/SECFIX it fix security permissions

Meanwhile I am adding  old blog articles links:

Backup - Robocopy and real time monitoring of any file changes

https://www.alessandromazzanti.com/2016/09/backup-robocopy-and-real-time.html

Scritping - Using robocopy to replicate files to remote location on scheduled tasks and sending final log and status email

https://www.alessandromazzanti.com/2014/01/scritping-use-robocopy-to-replicate.html

Backup – Lista dei comandi di Robocopy

https://www.alessandromazzanti.com/2013/02/backup-lista-dei-comandi-di-robocopy.html

Tips - How to migrate file server share and permissions

https://www.alessandromazzanti.com/2015/11/tips-how-to-migrate-file-server-share.html

Scripting - Inviare una mail da riga di comando in windows

https://www.alessandromazzanti.com/2011/01/inviare-una-mail-da-riga-di-comando-in.html

Windows 10 - HyperV installation for free

There is an interesting feature available on Windows 10.

HyperV capability permit you to easily create VM on your Windows 10 Laptop/PC/Workstation. Obviously same feature is available on Microsoft Windows server editions.

On Windows Server and Windows 10 your hardware must support virtualization.

You should decide if start using VM generation 1 or 2:

https://docs.microsoft.com/it-it/windows-server/virtualization/hyper-v/plan/should-i-create-a-generation-1-or-2-virtual-machine-in-hyper-v

https://www.windowserver.it/2014/03/hyper-v-vm-generation-2-deep-dive/

About ram there is dynamic memory feature.

Tips - Network Configuration Operators Group

If you have normal user permissions and you need to change network adapters TCP/IP configuration you can do that without having administrative rights. 

Infact you need to simple add your user to below local group

Network Configuration Operators





Server - Active Directory Time syncronization problems

During these years I faced, on server and clients, several authentication problems due to wrong time and date.

Here they are some commands and tips useful for this troubleshottoing purpose:

1. Command useful on DC to see any time differences in place and relative (offset)

w32tm /monitor 

2. Run the following command on the PDC emulator:  

w32tm /config /manualpeerlist:timeserver /syncfromflags:manual /reliable:yes /update

Once done, restart W32Time service.

net stop w32time | net start w32time 

3. Run the following command on all other DCs (that are not PDC):  

w32tm /config /syncfromflags:domhier /update

Once done, restart W32Time service:

net stop w32time | net start w32time 

I have often, in recent years, to solve problems of e-mail or authentication domain generated from misconfigurations time servers. 

4. To check the source time server: 

w32tm /query /status

5. 
You can check registry entries if the domain controller is using NTP (should be on PDC) or NT5DS (on non-PDC):
Find the value of Type under 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters

reg query 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters

6. re-sync the w32time service using the following command:

w32tm /resync /rediscover

<---------->
7. Execute the following command to actually perform a time synchronization with the external source

w32tm.exe /config /update


Some articles and tools

port query Tool GUI


https://www.microsoft.com/en-us/download/details.aspx?id=24009


Technet - Windows Time Service Tools and Settings


https://technet.microsoft.com/en-us/library/cc773263(v=ws.10).aspx

Time Configuration in Active Directory

http://blogs.technet.com/b/nepapfe/archive/2013/03/01/it-s-simple-time-configuration-in-active-directory.aspx

Configure DC to synchronize time with external NTP server

https://community.spiceworks.com/how_to/65413-configure-dc-to-synchronize-time-with-external-ntp-server


[update 2021.03.04]

Here they are register keys related to date and time Windows services

Microsoft Registry
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Config
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer



[update 2026.03.25]

w32tm /stripchart /computer:10.107.1.35 /dataonly /samples:5