Showing posts with label Windows 2022 Server. Show all posts
Showing posts with label Windows 2022 Server. Show all posts

Security #Windows Server Secure Boot playbook for certificates expiring in 2026

 

Windows Server Secure Boot playbook for certificates expiring in 2026

Learn about tools and options available to organizations to update Secure Boot certificates on Windows Server. Certificates begin expiring in June 2026. You must update them before that date to help keep your security posture. Many recent platforms already include the supported 2023 certificates in firmware. However, for the ones that need to be updated, you need to manage this process manually.

 

When will this happen: 

·     The tools are already available to help you to proactively inventory, monitor, and apply updated certificates to your Windows Server devices.

·     June 2026: The 2011 Secure Boot certificate authorities (CAs) begin expiring.

 

How this will affect your organization: 

Systems on the 2011 CAs after June 2026 are at risk of running on degraded security posture. To update these systems, please be proactive and follow our recommended approach.

 

What you need to do to prepare: 

Read complete guidance in Additional information for details on how to: 

1.  Inventory and prepare your environment.  

2.  Monitor and check your devices for Secure Boot status.  

3.  Apply any needed OEM firmware updates before updating certificates.  

4.  Plan and pilot Secure Boot certificate deployments.  

5.  Troubleshoot issues. 

 

here it is an interesting article with very detailed information

https://4sysops.com/archives/update-expiring-windows-secure-boot-certificates-now/

Windows Server Secure Boot playbook for certificates expiring in 2026

Update Secure Boot certificates on Windows Server and VMs before June 2026

Microsoft #Windows Server end of support Microsoft 365 Apps on Windows Server 2016, 2019, 2022, or 2025.

TOPIC: Microsoft 365 Apps (*) end of support (a.e. Word, Excel, Outlook ...) on Windows Server 2016, 2019, 2022, or 2025.

END OF SUPPORT DEADLINES until:

  • Windows Server 2025: October 2029
  • Windows Server 2022: October 2026
  • Windows Server 2019: October 2025
    • In the interest of maintaining security while customers complete their migrations to a supported configuration, Microsoft will continue providing security updates for Microsoft 365 desktop apps running on Windows Server 2019 for a total of three years, ending on October 10, 2028.(**)
  • Windows Server 2016: October 2025
    • In the interest of maintaining security while customers complete their migrations to a supported configuration, Microsoft will continue providing security updates for Microsoft 365 desktop apps running on Windows Server 2016 for a total of three years, ending on October 10, 2028. (**)
IMPACTS:
  1. Microsoft 365 Apps (*) will not be longer supported after previous deadlines  related to O.S. versions earlier mentioned (but it does not mean that they will stop immediately to work properly ) 
  2. These deadlined will affect Virtual Desktops environments such Citrix VDA and gold image...
(*) Word, Excel, Powerpoint, Outlook for email, OneNote, OneDrive, Teams, Sharepoint

[Original articles]

Microsoft 365 Apps migration from Windows Server

(**) Windows Server end of support and Microsoft 365 Apps 



https://www.linkedin.com/pulse/microsoft-windows-server-end-support-365-apps-2016-2019-mazzanti-olgre

Server #Error 0x800f0922 installing windows update KB5066793

On microsoft Windows server at the end of installing windows update KB5066793 (at 98%) the update rolls back and shows Error 0x800f0922 in windows update.

Solution is opening regedit.exe and delete this registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{53e3d721-2aa0-4743-b2db-299d872b8e3d}

More details con be found here

https://learn.microsoft.com/en-us/answers/questions/5597589/error-0x800f0922-installing-windows-update-kb50667

Edge #How to reset profile

If you need to reset Edge settings profile (you will lose only stored password, bookmarks can be easily reimported, plugin/extentions could be re-downloaded) you need to go to this path and rename following folder

C:\Users\%username%\AppData\Local\Microsoft\Edge\User Data\

https://learn.microsoft.com/en-us/answers/questions/1355083/delete-all-microsoft-edge-profiles-(complete-reset

https://angolodiwindows.com/2022/04/come-resettare-microsoft-edge/

Server #Take action: Disable Secure Time Seeding (STS) in Windows Server 2016 and later

Microsoft recommends disabling the Secure Time Seeding (STS) in Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 due to reported timekeeping issues. Additionally, organizations should review and ensure proper time synchronization and monitoring on critical servers.   

 
When will this happen:
Microsoft recommends applying this disablement as soon as possible. This recommendation applies to all existing deployments of Windows Server 2016 and later (including domain controllers and member servers).


more details could be found here:

Security #February 2025 Deadline related KB5014754 and Certificate-based authentication changes on Windows domain controllers

Microsoft released, several months ago this important bulletin.

The key point is that, after February 2025 patch installation Windows domain controller certificate-based authentication will change (due to security reasons) to Full Enforcement mode. However, you can move back to Compatibility mode until September 2025.

There are several CA checks to be done to be sure that no problem will affect your organization.

One compatibility doubt that it might arise it could be related to organization that have no longer supported O.S. (like 2008 or older)

I think that working in compatibility mode might help to check, on internet, after February 2025 if any customer had some issues and find relative fixes/workarounds

In any case here they are essential checks that you should consider before enable “full enforcement mode”:

  1. Common Name (CN) and Subject Alternative Name (SAN): Must match the users or devices in Active Directory.
  2. Certificate Authority (CA): Certificates must be issued by a trusted and recognized CA.
  3. Certificate Chain: The certificate chain (including intermediate and root CA certificates) must be complete and valid.
  4. Revocation: It is necessary to check that the certificates have not been revoked.
  5. Time Validity: It must be verified that the certificates have not expired


KB5014754: Certificate-based authentication changes on Windows domain controllers

https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16 

https://admin.microsoft.com/AdminPortal/home?#/MessageCenter/:/messages/MC894351


TEAMS & OFFICE #ERROR #vdi #citrix #2022 #how to fix

 On VDI environment new Teams version might have below problem evidence:


Otherwise you might not be able to logon on Teams having below error




Finally you might be asked to logon with your user account each time that you close an re-open Microsoft application such Word, Excel ...

These are steps necessary to fix problem.
  1. Logoff user from Teams/Office Application session.
  2. Close teams/Office program
  3. Delete this folder and all its content
    C:\Users\user\AppData\Local\packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
  4. Execute Teams/Office application once again

MICROSOFT #LSASS high usage #after patch installation #MARCH 2024 **how to fix**

Microsoft released bullettin advising customers experiencing excessive memory consumption by LSASS on Windows Server 2012-2022 DCs that have installed the following Windows Update(s): 

KB 5035857: March 12, 2024, KB5035857 (OS Build 20348.2340) Windows Server 2022 

KB 5035849: March 12, 2024, KB5035849 (OS Build 17763.5576) Windows Server 2019 

KB 5035855: March 14, 2024, KB5035855 (OS Build 14393.5786) Windows Server 2016

KB 5035885: March 12, 2024, KB5035885 Monthly Rollup for Windows Server 2012 R2: March 12, 2024 

Fortunately, there are workable solutions that you can use to address the high LSASS usage after the 3b Windows update has been installed.

https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#march-2024

Workarounds suggested by Microsoft are related to install below fix

https://support.microsoft.com/en-us/topic/march-22-2024-kb5037422-os-build-20348-2342-out-of-band-e8f5bf56-c7cb-4051-bd5c-cc35963b18f3

[original article]

https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/this-just-in-high-lsass-usage-after-windows-update-3b-march-2024/ba-p/4096250

TEAMS #new for Virtualized Desktop Infrascructure (VDI) #deadline 30/06/2024 **no longer supported on 2016**

IMPORTANT

Microsoft announced that Classic Teams for VDI will reach end of availability on June 30th, 2024.

In case your VDI farm is on Windows Server 2016 this is no longer supported, consider previous announcement you must plan VDI migration asap.

Original article

https://learn.microsoft.com/en-us/microsoftteams/new-teams-vdi-requirements-deploy

Other important blog articles:

Teams #New Virtual Desktop Infrastructure solution #MC717969 **CITRIX**365**AZURE**

Office - Microsoft 365 Apps and operative system supported roadmap

  • Windows Server 2016: October 2025
  • Windows Server 2019: October 2025
  • Windows Server 2022: October 2026

[update 2024.06.24]

about this topic there these new dealines

https://learn.microsoft.com/en-us/microsoftteams/new-teams-vdi-requirements-deploy#requirements



Teams #New Virtual Desktop Infrastructure solution #MC717969 **CITRIX**365**AZURE**

Microsoft announced that The new Virtual Desktop Infrastructure (VDI) solution for Microsoft Teams is a redesigned version of the existing VDI optimization (WebRTC based) 

This release applies to Microsoft Windows endpoints connecting to Microsoft Azure Virtual Desktops, Microsoft Windows 365, and Citrix VDI environments only.

Citrix Workspace app for Windows (2203 Long Term Service Release [LTSR], or 2302 Current Release [CR] or higher)

When this will happen:

Targeted Release: We will begin rolling out early April 2024 and expect to complete by late April 2024.

Standard Release: We will begin rolling out in late April 2024 and expect to complete by early May 2024.

This message is associated with Microsoft 365 Roadmap ID 375418

more details might be found here:


Office - Microsoft 365 Apps and operative system supported roadmap

I am taking note about fact that Microsoft 365 Apps is supported on the following versions of Windows Server until the dates specified:

  • Windows Server 2016: October 2025
  • Windows Server 2019: October 2025
  • Windows Server 2022: October 2026

This news will strongly affect infrastrucures where VDI are used on previously O.S. 

https://learn.microsoft.com/en-us/deployoffice/endofsupport/windows-server-migration

Server - How to debug DNS queries on Domain Controllers

On windows Server environment, it could be useful to debug and save any DNS query submitted to your domain controllers/DNS servers.

There is an easy way to achieve this goal.

In fact you need to enable DNS debugging mode.

After this feature is enabled you can check logs and identify devices that are querying specific DNS entries/websites.

This approach it is useful, at first, about security interdipendence as well...

  1. Open DNS Manager (dnsmgmt.msc)
  2. Right-click the DNS server and click Properties.
  3. Click the Debug Logging tab.
  4. Select Log packets for debugging.
  5. Enter the File path and name, and Maximum size.


[related articles]

2016 #Multiple RDP connections #how to bypass 2 session limit

If you need to allow RDP multiple connection to windows 2016 server you can follow below procedure.

Be aware that alrerady installed internal RDS cal server is a prerequisite

Here they are minimal steps that need to be followed:

  1. Go to Server Manager in Windows Server 2016
  2. Click Add Roles and Features
  3. Then select Role-based or feature-based installation
  4. Choose:  Remote Desktop Services
  5. Then choose:  Remote Desktop Session Host
  6. Install the role
  7. restart server
  8. GDPEdit.msc
  9. Go to Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Connections
    • Set Limit number of connections to Disable.
    • Set Restrict Remote Desktop Services users to a single session to Disable.
    • Set Limit number of connections to enabled 999999
  10. Go to Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Remote Desktop Services -> Remote Desktop Session Host -> Licensing
    • Set Use the specified Remote Desktop license servers to enabled (indicate FQDN server name)
    • Set the Remote Desktop licensing mode to enabled (Per User or Per Device)
  11. gpupdate /force
  12. Test multiple RDP connections
  13. Launch RD Licensing Diagnoser snap-in to check that everything is working properly.


Windows - How to throttling Network file transfer speed

I am taking note, on blog, about an interesting article that explain several ways used to limit bandwitch usage during file transfer.

From my side, GPO, related to QoS was decisevely useful.

https://woshub.com/limit-network-file-transfer-speed-windows/

Security - Sophos AV stop definitions updates #WORKAROUND & #DETAILS **JULY 2023**

During these latter weeks Sophos released new AV version. (Core Agent 2023.1/Server Core Agent 2023.1 )

PROBLEM

  • This letter Sophos version require that these O.S. have propter September 2021 patches installed.
  • In case you are not on track with MS updates or Windows version it will occur this problem
  • End point Sophos definition updates will stop working
    • Client: Early of July 2023
    • Server: End of July 2023

AFFECTED SYSTEMS AND DEVICES

    • Windows computers:
      • From early-June 2023, Windows 10 (x64) operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Core Agent 2023.1 and above.
    • Windows servers:
      • From late-July 2023, Windows 2016 operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Server Core Agent 2023.1 and above.

  WORKAROUND APPLICABLE TO POSTPONE PROBLEM

  • The Software Packages functionality in Sophos Central can be used to assign devices to a Fixed term support (FTS) version.
  • The current version for Windows computers and servers is FTS 2022.4.3.2 and can be assigned to devices for the duration of time it takes to apply the Windows Security Updates.
  • Note: There is an expiry date for all software package versions after which devices will stop updating.
    • The expiry date for FTS 2022.4.3.2 on Windows computers is October 10, 2023.
    • The expiry date for FTS 2022.4.3.2 on Windows servers is November 14, 2023.
  • To achieve this goal you must modify Update Management policy as indicated in below screenshots.

 


APPENDIX

Full details on required updates can be found in Microsoft’s official KB5022661 on this topic. 
https://support.microsoft.com/en-gb/topic/kb5022661-windows-support-for-the-azure-code-signing-program-4b505a31-fa1e-4ea6-85dd-6630229e8ef4

In addition to having the required Windows Security Updates to verify modules signed by Azure Code Signing, devices must have the "Microsoft Identity Verification Root Certificate Authority 2020" certificate authority (CA) installed.

Generally impacted O.S. are Windows 10/11 and Windows 2016/2019/2021 server versions.

Legacy O.S. are not impacted:

Windows 8.1

  1. Windows Server 2012 R2
  2. Windows Server 2012
  3. Windows 7.0 SP1
  4. Windows Server 2008 R2
  5. Windows Server 2008 SP2 

New Installation

From the 18th of April 2023, new installations to operating systems that don't support Azure Code Signing (ACS) will fail.

Active Directory - FSMO Seizing, DRSM Password Reset and Dc health checks/best practices

As mentioned on old blog posts it is important to know which DCs (in your domain/Forest) are holding five Active directory roles using this command line.

netdom query fsmo

At the same time it is important to test your DCs health.

https://www.alessandromazzanti.com/2015/05/server-commands-to-verify-domain.html.

If you are facing unlike situation that DCs holding all 5 Ad roles (or few of them)  are no longer working you should start planning Seizing roles activity.

Here it is a Microsoft article that well apply to all Microsoft Server versions.

https://support.microsoft.com/en-sg/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control

Here they are other important suggests:
  1. Microsoft best practices suggest to have at least a Physical Domain controller indeed to have all them virtualized:
  2. I warmly suggest to check all your server and to have local Administrator password (and account enabled).
  3. To check, on all your servers/Dcs to have indicated DNS1, DNS2 and DNS3 pointing to active DCs/DNS
  4. Have 5 AD roles splitted between at least two domain controllers.
  5. About Domain controllers have DRSM Administrator password, if not known proceed to have it resetted.




Windows Server - AD cleanup/Removal DC procedure

On AD Microsoft server infrastructure it might happen that a DC death suddenly and there is any possibility to recover it (other than format/delete/wipe it)

In this specific case furthermore, you should cleanup AD metadata (to delete any referring that specific DC).

I am taking note, on blog, procedure (saving some articles that I used, in the past, to find workflow):

Metadata Cleanup Using NTDSUTIL in Windows Server 2008 R2
Clean Up Server Metadata

[Update 2022-08.02]

GPO - How to create local Administrator account using Group policies

If you want that all Pcs/server under same OU will have automatically created a new local Administrator account with a specified password you can do that creating a precise GPO.

I already tested procedure in the past and it worked fine (with centralized management):


  1. Launch Group Policy Management console --> "create a GPO...." --> Group Policy Editor
  2. Navigate to Computer Configuration\Preferences\Control Panel Settings\Local Users and Groups 
  3. right clieck in blank area and select New --> Local User
  4. Action --> update
  5. User name --> testadmuser
  6. You can setting up other settings.
  7. Put testadmuser password
  8. you can repeat precedent procedure about Administrator Account (built-in), 
If you like you can review this article too

http://www.dannyeckes.com/create-local-admin-group-policy-gpo/

I would like to highlight this article that clearly explain how to decrypt stored AD password for local administrator account using precedently GPO and how to enforce security with Microsoft Premier support.

https://blogs.technet.microsoft.com/askpfeplat/2014/05/18/how-to-automate-changing-the-local-administrator-password/

[update 2024.05.24]
in case you need to add an AD user Administrators members group you need to follow these steps

1. Launch Group Policy Management console --> "create a GPO...." --> Group Policy Editor
2. Navigate to Computer Configuration\Preferences\Control Panel Settings\Local Users and Groups 
3. right clieck in blank area and select New --> Local Group
4. Action --> update
5. Group name --> Administrators (built-in)
6. You can setting up other settings.
7. Members, Add --> Search for the Service Account in AD 
8. Action--> Add to this group