CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability
Hi All https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900 To remediate the vulnerability CVE-2013-3900 is to add the below registry values. [HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config] …
Windows Server 2019
Windows Server 2016
Windows Server
Windows Server Security
Converting Trusted Azure VMs to Standard VMs
I have created a Windows Server VM with Trusted Launch Virtual Machine and am unable to add it to Azure Site Recovery. Is there a way to convert the running VM to a standard VM? Additionally, I am unable to add backups to a standard backup policy.
Azure Backup
Azure Virtual Machines
Azure Site Recovery
Windows Server Security
Windows Server Infrastructure

Open ports are shown as blocked
Hello, I have a question regarding the installation of an Exchange Server 2016. Currently, I am getting error messages at testconnectivity.microsoft.com regarding closed ports: "Testing TCP port 443 on host autodiscover.DOMAIN:TLD to ensure…
Windows Server Security
Windows Server

Microsoft Defender Antivirus Vs Symantec Endpoint Protection
Hi, We are looking into replace Symantec Endpoint Protection with Microsoft Defender and have some questions. Our environment is as follow 100 servers (Windows Server 2003, 2008 R2, 2012 R2, 2016 and 2019) 100 clients (Windows 7 Ent, Windows…
Windows 10 Security
Windows Server Security
Windows Server

Enable Bitlocker On file Server
Hi, Our Security team decides to use BitLocker encryption on file server disks, my question does it supported or not. does the user will be able to access the shared files after enables BitLocker. Thanks
Windows Server 2019
Windows Server 2016
Windows Server Security
Windows Server

PKI: can a SubCA be signed by another RootCA than the original?
Hi, Can an existing Enterprise Subordinate CA be signed by a new Root CA? This SubCA will be revoked by the original Root, as it will no longer be part of the current hierarchy. Our client may want to have the SubCA continue running without having to…
Windows Server Security
Windows Server Infrastructure
Windows Server

IP is not resolving while doing nslookup
Hi I have removed DNS from my server and I have added the destination host IP in the Hosts file. After doing NSLOOUP I am getting error as IP is not resolved. Can someone please help me?
Windows Server 2016
Windows DHCP
Windows Server Security
Windows Server

PowersShell Trusted Hosts Illusive Windows Server 2016 Interactions.
Hello I am having a Issue where I want to talk to my nanosever in PowerShell, however I must add in the other subnetted addresses when the DHCP changes for nanoserver and it jumps subnets so I can PSSession back into it. I have added the new sever IP…
Windows Server 2016
Windows Server Security
Windows Server

Migrating CA from 2012R2 to 2019 problem
I'm trying to migrate an Enterprise Subordinate CA from a 2012R2 DC to a new 2019 DC. The 2012R2 CA was in itself an upgrade from 2008 R2, and that migration worked without a problem. I'm using the proper documented process, but am experiencing two…
Windows Server Security
Windows Server

Does recents security updates include previous fixes ?
Hello Dears, I need your answer on this subject, regarding windows servers updates. Say i download and install security updates for November 2020, will that include previous fix for ZeroLogon patch released on August 11th 2020 ? Thank you in…
Windows Server Security
Windows Server

Active Directory Certificate Servicces wont start Win2019 Core
Hi all, Hoping someone can help me as I am puzzled. I currently am building a Sub-CA , I received the signed cert from the Offline root, installed it on the Sub CA and verified it can talk to the keys on the HSM. This all checks out. However when…
Windows Server 2019
Active Directory
Windows Server Security
Windows Server

Setup an additional subCA with existing key
Hello everybody, we have a two tier CA with an offline RootCA and two subordinate CAs (Lets call them Sub1 and Sub2). Now we would like to add an additional SubCA and then remove Sub1. What happens when I setup the new SubCA with the existing private…
Windows Server Security
Windows Server

Migrate PKI from Windows 2012 to Windows 2019
Hi, We are looking to upgrade the operating system of our PKI from windows server 2012 to windows 2019. Should I upgrade the SHA1 before or it will be done during the PKI migration ?
Windows Server 2019
Active Directory
Windows Server Security
Windows Server

Windows clustered file Server 2008 R2 problems accessing to shared folders.
I will try to describe a problem as detail as I can. The problem is that workstations that are part of System911.com windows ___domain are access to shared folders on file server. File server are part of another windows ___domain sovi.sk. All machines…
Windows Server Security
Windows Server Infrastructure
Windows Server Storage
Windows Server

Smart card RDP logon weird behavior 2
Hi! This spring I first faced strange situation described here: https://social.technet.microsoft.com/Forums/en-US/6e7e86aa-6cec-407c-9a18-dde090fccc0a/smart-card-rdp-logon-weird-behavior?forum=winserverTS Now I see it again in different environment.…
Remote Desktop
Windows Server Security
Windows Server

Why when I deploy my roots and intermediate CA Certificates to AD do some servers automatically download them and others do not?
I am very confused by the process of publishing Root and Intermediate certificates to AD and how they deploy to servers across an enterprise. When I publish the Root and Intermediate CA certs to the AIA and Certification Authorities Containers in AD,…
Active Directory
Windows Server Security
Windows Server

Vulnerability scan and Windows Update KB4025339
Hi all, In a company has been done a Vulnerability assessment using a dedicated software. Vulnerability reports talks about a missing Windows Update on a VM with Windows 2016 Datacenter The fix is install KB4025339 (more details here:…
Windows Server Security
Windows Server

How to capture audit log for the following packet filters DR-F0401-032, DR-F0401-036, DR-F0401-037 and DR-F0401-117?
How to capture audit log for the following packet filters DR-F0401-032, DR-F0401-036, DR-F0401-037 and DR-F0401-117?
Windows Server 2016
Windows Server Security
Windows Server

How to identify strong and weak ciphers?
Hi All, We have a doubt on how to identify the strong and weak ciphers from below: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030) TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028) TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) Can anyone help me…
Windows Server 2016
Windows Server Security
Windows Server

SMB Signing not required vulnerability
This regarding below fixes where I need difference between the two fixes and clarifications: As per the below article, Once I updated Microsoft network server: Digitally sign communications (always). value as Enabled the vulnerability is not seen in…
Windows Server 2016
Windows Server Security
Windows Server
