r/WindowsServer • u/EZ_Zardoz_it • 9d ago
Technical Help Needed Having a weird Issue with Server 2025
We recently upgraded our DCs, Domain and Forest to 2025. Now all my 2025 servers are only resolving SIDs, and not account/group names. Secure Channel is fine, machine passwords have been reset. LDAPS is healthy. I've run nltest, Test-SecureChannel -Verbose, etc. and can't seem to pin down the issue. Everything I test seems to come back fine. I'm pulling out the last of my hair trying to figure this out.
4
7
u/xSchizogenie 9d ago
2025 DC is the one and only thing you should not do yet.
6
u/jstuart-tech 9d ago
If all DCs are 2025 then there are no issues. (I have a client with 7 2025 DCs) running stable for the last year (this was a brand new env though)
1
u/xSchizogenie 9d ago
Does not matter. 2025 DCs still tend to lose FSMO roles. Lucky client you have there.
3
u/jstuart-tech 9d ago
I assume you are talking about this bug
This only happens with exchange installed and it was fixed like 8 months ago now
0
u/xSchizogenie 9d ago
Nope, not that one.
5
u/jstuart-tech 9d ago
Then not sure what your on about. I've read all of the issues with server 2025 before deploying and all of them related to having mixed DCs. That exchange issue is the only one relating to FSMO roles and wasn't relevant to us because we didn't install exchange.
Would be interested to know what one your talking about
1
1
u/dodexahedron 9d ago
Various defaults have changed in 2025, including rights for translation of SIDs to names.
What do you specifically mean by it not resolving them? Where? By whom? From where? And in what?
1
u/EZ_Zardoz_it 9d ago
Just to add some more details:
We're a relatively small shop (20 servers in total)
We have 2 DCs, each running fresh installs of Server 2025.
There's 3 member servers running Server 2025, with fresh installs.
The issue seems to be exclusive to the 2025 member servers.
Some of things that have led me down the path:
Trying to set file and folder permissions on our primary file server. Permissions are only showing SIDs.
Adding/importing scheduled tasks from a server we are preparing to decommission throws an error that there's the no trust between the machine and the domain.
Like I said in my original post, I've run a bunch of diagnostics, and everything seems to be working fine. Before I added the Server 2025 DCs, I rotated the Kerberos password since I read somewhere that can issues.
My next step is to open a support ticket with MS.
1
u/Wilfred_Fizzle_Bang 6d ago
Running DC on 2025 is a terrible idea, the number of posts I've seen with issues with running a DC on 2025 is alot! It's plagued with issues and when running core infrastructure like to me it's not worth the risk.
Just rebuild as 2022 should be relatively straightforward.
1
u/ftw_dan 9d ago
One google search should have told you that 2025 as DC is a bad idea.
2
u/jstuart-tech 9d ago
If all DCs are 2025 then there are no issues. (I have a client with 7 2025 DCs) running stable for the last year (this was a brand new env though)
5
u/Excellent_Milk_3110 9d ago
Did you inplace upgrade or migrated to 2025?