Friday, July 20, 2012

Is It a Domain Controller

I recently went into our test lab and there was a guy working in there and he asked me.

If I'm on a machine how do I know if it is a Domain Controller
These are often my favorite types of questions.  No time to check Bing/Google, no time to check a book.  Just a quick question that is answered in seconds.   By the way in those situations it is also ok to say "I don't know" or "I'll get back to you".  A lot of times you will see people blowing smoke and making stuff up.

The guy wasn't trying to be an ass but trying to learn AD and the lab is a perfect place for it.  We have a lot of VMs in our lab and I didn't know what box he was on when I walked in.

My initial thought was to tell him to look for admin tools etc but then after a second I realized not every box has the admin tools installed.  Then I thought look for the AD Domain Services and see if they are started.  That thought lasted for a half second.  We still have 2003 DCs too so if he was on one of those then no services.

The answer I gave him was to run:

net share 


If the sysvol share is present then it is a domain controller.








I started thinking of other ways and reached out to some friends and asked what they would have suggested for this quick question.


One suggestion by my friend Troy was to run


netdom query dc


I thought that was a good one and team that with hostname so that the person knows the name of the machine works great.



My buddy Eric had a good one, it is a bit more involved because it would require the person to know about AD ports...but if they are learning they should know some of these. Use netstat -ano and look for AD ports (88, 389, 3268, and others)

netstat -ano  or netstat -ano | findstr /i listening




There are a lot of ways to do this.  You could look for SRV records.  If ADUC was installed you could have them check there for the DC.

If you also look at the drop down when you login and it has no local server name then that is another good indication.  In this case he was already logged in.

So what answers would you have given?  Are there quicker easier ways that you would have told someone just starting out with AD to check if they are at a domain controller?

Update from Kurt (thanks for your service in the Army...in war zones).    I posed this question to a mid-level AD admin.  His response was "run dcpromo, it will tell you if it is a DC".   That is true and something I didn't think of in the 5 second response.  This is why I love AD...so many ways to do something and a lot of great solutions.

My only caveat about this method is that if someone was being careless didn't read and clicked next next and finished the wizard then they could also be demoting a DC....I'm hoping people using AD can read :)

In the example below the computer is obviously a DC.




Note: The dcpromo method won't work in Windows 2012...because they killed that off...more on that in future posts.   I'm guessing very few folks are currently running Windows 2012 in production.  Example of start > run > dcpromo on a Windows 2012 DC below.




Update 2: Krzystof  had a great suggestion in the comments and that was to use systeminfo 

systeminfo /i "os configruation"




Friday, July 13, 2012

Speaking at Microsoft TechGate Conference on 9/15

This mainly applies to readers that are in the DC, Virginia, and Maryland region as I don't think anyone is going to fly in for this :)

Microsoft is sponsoring TechGate 2012 on September 15, 2012 at their Reston, VA office.  There are 15 sessions and five workshops so it should be a good day.  It will also not be 100 degrees every day by that time so come out if you can.

You can find more information and register for the conference here:



As you can see I will be speaking about new Active Directory features in Windows Server 2012.  I'm really looking forward to it.  l'm also hoping to devote 10 minutes at the end to discuss what features folks would like to see in R2 or future versions.  That is feedback I'll take back to the AD team during the MVP summit in early 2013.

I'm really looking forward to meeting other members of the DC IT community in a few months.

Monday, July 2, 2012

MVP Award - Year Four

I woke up yesterday to great news that I've been awarded the MVP award in Directory Services for the fourth year.  I have previously written blogs with long thank you lists so I won't do that again.  Just a continued huge thanks to everyone I mentioned in those two blog entries.  I've learned from a lot of people and glad to help others.

My favorite part about being an MVP is the MVP summit and I'm really looking forward to going to Seattle again in the late winter.

This is an exciting time for Active Directory.  Windows 2012 is being released later this year.  Windows Azure Active Directory is coming online.  We will have a lot to learn but that is the fun part for me.


Thursday, May 24, 2012

Outstanding Cloud & Identity Talk

I generally don't post videos or presentations as blog entries but this is one I haven't seen posted by a lot of folks and is a must watch for anyone in the Identity, Active Directory, Directory Services field.

The main reason I love this talk is because the presenter.  Microsoft's Kim Cameron     Kim is the Chief Architect of Identity in the Identity and Access Division at Microsoft.  In other words when it comes to anything Active Directory/DS.  Kim is "the man"

Vittorio had an excellent blog about Kim   (Kim was retiring when that blog was written but has come back and he talked about that in this presentation)


This is a twenty minute Kim's keynote from the European Identity & Cloud Conference 2012.

Some things I liked


  • Use the efficiencies of the cloud to enable efficiencies in identity
  • The Cloud Motor Runs on Identity
  • Identity Management as a service is an inevitability
  • There ae other vendors who have similar directories...not as good of course :)
There are a lot of people that talk about the cloud and give talks.  This is one from a guy who truly knows his stuff.   Kim also has an excellent blog entry that goes with this video.

I'm personally excited that AD and Directory Services types can evolve our skills and have work for years to come.





Monday, April 16, 2012

New MCSE - Personal FAQs

As most blog readers know Microsoft has brought back the MCSE & MCSA certifications and titles.  For those newer to the field the MCSE was one of Microsoft's most popular certifications and tracks.  I'm on the AD/Server side of the house so for me this goes back to an MCSE in Windows NT, 2000, & 2003.

With the 2008 tracks Microsoft did away with the MCSE & MCSA and introduced the MCITP an MCTS tracks and certifications.

The MCSE and MCSA are back again but this time they stand for

Microsoft Certified Solutions Expert
Microsoft Certified Solutions Associate

The Microsoft Learning team has put together a nice page with a lot of information.


There are also some good videos on the site and the Microsoft Learning YouTube Channel




There was a lot of great information on the site, but I still had questions and after asking around I noticed others had the same questions.  MSLearning has a Twitter Account and that is where I learned a lot more about the new certs and the future. I compiled some of my FAQs here:




MK FAQ 1 : What happens if I have the MCITP:SA do I need to start from scratch?



So that was good news, as you can see the MCITP:SA will automatically receive the new MCSA: Windows Server 2008 Certification.


MK FAQ 2 : What happens if I have the MCITP:EA?



This was interesting because the MCITP: EA and MCITP: SA will both have the same MCSA: WS2008 title.   I was hoping for two certs as I have both :)   

Note: It was common for people to get both the MCITP:EA and MCITP:SA certifications.

MK FAQ 3 : When will our transcripts be updated?

According to the twitter conversation above transcripts should change on April 24, 2012.

UPDATE:  Blog reader let me know in the comments that his transcript was updated on 4/17/2012.  Nice job by Microsoft getting ahead of schedule.


MK FAQ 4 : What happens to our old certifications?





This one I really like a lot!   I like that old certs will enter a legacy state and be stated that way on the official Microsoft transcript.

I also like that new exams and certifications will also retire.  It makes people need to stay somewhat current and re-certify.  Other companies already use the model the most famous probably being Cisco.   

I know there are going to be cynics out there that remember MCSE's being referred to as "paper tigers" or MCSEs that got their certs through brain dumps and that made us all look bad but Microsoft is definitely moving in the right direction in my opinion.

I'll take an analogy from the Army.  Every Army soldier goes through bootcamp and has "basic" skills but there is a lot more training and experience needed to become a Ranger or Special forces and deal with the advanced issues/topics.   That is how I look at a lot of these certs (from any company).  They are a good step but getting an MCSA or MCSE doesn't mean someone knows everything....it is an ongoing process.

One of my AD Heroes is Joe Richards and he once rated himself a 6 out of 10 in AD.   Again it is a lifelong learning process...no one knows it all not even a guy like Joe (love how humble and cool he is)

I'd like to hear from the community.  What do you think about the new changes and updates?


Wednesday, April 4, 2012

Security Compliance Manager 2.5 Released

Ned Pyle wrote a blog entry in January on the  Microsoft askds blog  about Security Compliance Manager 2.5 Beta

The tool has been officially released and is no longer in beta.

From the download center

We are pleased to announce that version 2.5 is released and now available for download from the Microsoft Download Center!
          Download SCM 2.5 now


I've been testing 2.5 Beta and really glad that it is now out of beta as it will be much easier to get the tool approved for use where I work.

You can read about the key features & benefits on the Microsoft site so I won't copy and paste them again here.

There will be follow up blog posts with more info and screen shots from the tool.


Friday, March 30, 2012

Active Directory Administrative Center Twitter Question

I recently saw a question on Twitter about the Active Directory Administrative Center (ADAC)

Twitter is a site everyone knows but more and more it is a great place for tech information and sharing in the community.  There are a lot of good tweets on Active Directory and links to information.  There is also a fair amount of spam/bad links.  Those are usually easy to spot though (picture is a "sexy" model for example)

Thanks a lot to @SamErde for letting me use his post for this blog.





ADAC was released with Windows 2008 R2.  It has gained some traction but currently it is definitely still not the GUI tool of choice for Active Directory Administration.  AD Users & Computers still wins but that may change in Windows 8 when features like the AD Recycle Bin and Fine-Grained Passwords are brought into ADAC giving both of those features a much needed GUI.

In order to truly test I created three forests in my lab and created a forest trusts between the first forest and the other two forests.  I did see TechNet articles that this could be done but I like to verify.





I'm not just a blogger I also work in this world and I know setting up the trusts can be a pain.  You have to have proper ports open  That is often easier said than done.  Become friends with the firewall admins :)   You also need to ensure that name resolution is working.  I used conditional forwarders to resolve the domain names in DNS.  Stub zones and secondary zones would also work.

There are a lot of posts and resources about setting up trusts.  If you run into issues look at the basics first
  • For potential port blockages tools like telnet, portqry, wireshark, and netmon are really good starting points.
  • For DNS issues nslookup is a good place to start troubleshooting.  (wireshark/netmon are good there too)



At this point the forest trusts have been setup and the two way trusts are functional.   The first thing we need to do is to try and add one of the other domains in ADAC.


Add Navigation Nodes in ADAC - Windows Server 2008 R2



Add Navigation Nodes in ADAC - Windows Server 8 Beta


I added the screenshot from a Windows Server 8 Beta box just to show that the location for adding the Navigation Nodes has changed.

I'm going to use Windows 2008 R2 for the rest of the examples.   I select add navigation nodes from there I can add another domain.  

Adding domain in another forest to ADAC via Navigation Node

Once I add the domain from the trusted forest I can now see it in ADAC

Remote domain from trusted forest now appears in ADAC

That is great but what does that really get me?  I am able to view objects in the remote domain due to the default nature of AD allowing read access to most objects.

I'm not able to make any changes which is a good thing.  The fact that the forest trust exists doesn't give any rights to administer the remote domain.

Notice in the screenshot below, I attempt to update/edit a user in the remote forest/domain.  I'm unable to make any changes but can read his info.

Attempting to update a user 

Without any rights I can't really do much.  In this case I want the same account to be able the objects in both forests.

There are several options here but I added my admin account into the Built-In Administrators group in the remote domain.


My admin account has been added into the Administrators group in the remote domain


After the addition has replicated I then try to update the user account from ADAC again.  This time you will notice that the fields are not grayed out and I can make changes.



Wishlist:  I would like the ability to add another domain in the navigation node but also specify alternate credentials when I do that.  That would be handy if an admin has a separate admin account in the remote forest/domain.   I'm still researching that and will update the blog if I find something.

There is a good article about ADAC on TechNet that is worth reading.  

What are your thoughts on ADAC.  For those at 2008 R2 is it gaining traction in your environments?