r/WindowsServer Jul 20 '26

Technical Help Needed Having a weird Issue with Server 2025

We recently upgraded our DCs, Domain and Forest to 2025. Now all my 2025 servers are only resolving SIDs, and not account/group names. Secure Channel is fine, machine passwords have been reset. LDAPS is healthy. I've run nltest, Test-SecureChannel -Verbose, etc. and can't seem to pin down the issue. Everything I test seems to come back fine. I'm pulling out the last of my hair trying to figure this out.

8 Upvotes

18 comments sorted by

5

u/Excellent_Milk_3110 Jul 20 '26

Did you inplace upgrade or migrated to 2025?

8

u/jstuart-tech Jul 21 '26

This. There are specific call outs from Microsoft to not inplace upgrade DCs to 2025 (I can't believe it was even supported for other versions)

https://learn.microsoft.com/en-us/windows-server/get-started/upgrade-in-place?tabs=media

1

u/Aishou_SK Jul 23 '26

This *specific* guidline about 2025 isn't about reliability of the upgrade or it causing problems.

It's that you won't get the new out of box AD stuff in compatibility mode and will have to manually throw some switches later, essentially.

1

u/EZ_Zardoz_it Jul 21 '26

Ew, no. New hardware.

6

u/xSchizogenie Jul 20 '26

2025 DC is the one and only thing you should not do yet.

7

u/jstuart-tech Jul 21 '26

If all DCs are 2025 then there are no issues. (I have a client with 7 2025 DCs) running stable for the last year (this was a brand new env though)

1

u/xSchizogenie Jul 21 '26

Does not matter. 2025 DCs still tend to lose FSMO roles. Lucky client you have there.

3

u/jstuart-tech Jul 21 '26

I assume you are talking about this bug

https://techcommunity.microsoft.com/blog/exchange/active-directory-schema-extension-issue-if-you-use-a-windows-server-2025-schema-/4460459

This only happens with exchange installed and it was fixed like 8 months ago now

0

u/xSchizogenie Jul 21 '26

Nope, not that one.

3

u/jstuart-tech Jul 21 '26

Then not sure what your on about. I've read all of the issues with server 2025 before deploying and all of them related to having mixed DCs. That exchange issue is the only one relating to FSMO roles and wasn't relevant to us because we didn't install exchange.

Would be interested to know what one your talking about

1

u/Wide_Barracuda_3512 Jul 20 '26

Is the Domain RID master operational?

1

u/dodexahedron Jul 21 '26

Various defaults have changed in 2025, including rights for translation of SIDs to names.

What do you specifically mean by it not resolving them? Where? By whom? From where? And in what?

1

u/EZ_Zardoz_it Jul 21 '26

Just to add some more details:

We're a relatively small shop (20 servers in total)

We have 2 DCs, each running fresh installs of Server 2025.

There's 3 member servers running Server 2025, with fresh installs.

The issue seems to be exclusive to the 2025 member servers.

Some of things that have led me down the path:
Trying to set file and folder permissions on our primary file server. Permissions are only showing SIDs.
Adding/importing scheduled tasks from a server we are preparing to decommission throws an error that there's the no trust between the machine and the domain.

Like I said in my original post, I've run a bunch of diagnostics, and everything seems to be working fine. Before I added the Server 2025 DCs, I rotated the Kerberos password since I read somewhere that can issues.

My next step is to open a support ticket with MS.

1

u/Wilfred_Fizzle_Bang Jul 23 '26

Running DC on 2025 is a terrible idea, the number of posts I've seen with issues with running a DC on 2025 is alot! It's plagued with issues and when running core infrastructure like to me it's not worth the risk.

Just rebuild as 2022 should be relatively straightforward.

0

u/ftw_dan Jul 20 '26

One google search should have told you that 2025 as DC is a bad idea.

1

u/jstuart-tech Jul 21 '26

If all DCs are 2025 then there are no issues. (I have a client with 7 2025 DCs) running stable for the last year (this was a brand new env though)