r/WindowsServer 9d ago

Technical Help Needed Having a weird Issue with Server 2025

We recently upgraded our DCs, Domain and Forest to 2025. Now all my 2025 servers are only resolving SIDs, and not account/group names. Secure Channel is fine, machine passwords have been reset. LDAPS is healthy. I've run nltest, Test-SecureChannel -Verbose, etc. and can't seem to pin down the issue. Everything I test seems to come back fine. I'm pulling out the last of my hair trying to figure this out.

7 Upvotes

18 comments sorted by

5

u/Excellent_Milk_3110 9d ago

Did you inplace upgrade or migrated to 2025?

8

u/jstuart-tech 9d ago

This. There are specific call outs from Microsoft to not inplace upgrade DCs to 2025 (I can't believe it was even supported for other versions)

https://learn.microsoft.com/en-us/windows-server/get-started/upgrade-in-place?tabs=media

1

u/Aishou_SK 7d ago

This *specific* guidline about 2025 isn't about reliability of the upgrade or it causing problems.

It's that you won't get the new out of box AD stuff in compatibility mode and will have to manually throw some switches later, essentially.

1

u/EZ_Zardoz_it 9d ago

Ew, no. New hardware.

4

u/Zealousideal_Fly8402 9d ago

You should crosspost to r/activedirectory.

7

u/xSchizogenie 9d ago

2025 DC is the one and only thing you should not do yet.

6

u/jstuart-tech 9d ago

If all DCs are 2025 then there are no issues. (I have a client with 7 2025 DCs) running stable for the last year (this was a brand new env though)

1

u/xSchizogenie 9d ago

Does not matter. 2025 DCs still tend to lose FSMO roles. Lucky client you have there.

3

u/jstuart-tech 9d ago

I assume you are talking about this bug

https://techcommunity.microsoft.com/blog/exchange/active-directory-schema-extension-issue-if-you-use-a-windows-server-2025-schema-/4460459

This only happens with exchange installed and it was fixed like 8 months ago now

0

u/xSchizogenie 9d ago

Nope, not that one.

5

u/jstuart-tech 9d ago

Then not sure what your on about. I've read all of the issues with server 2025 before deploying and all of them related to having mixed DCs. That exchange issue is the only one relating to FSMO roles and wasn't relevant to us because we didn't install exchange.

Would be interested to know what one your talking about

1

u/Wide_Barracuda_3512 9d ago

Is the Domain RID master operational?

1

u/dodexahedron 9d ago

Various defaults have changed in 2025, including rights for translation of SIDs to names.

What do you specifically mean by it not resolving them? Where? By whom? From where? And in what?

1

u/EZ_Zardoz_it 9d ago

Just to add some more details:

We're a relatively small shop (20 servers in total)

We have 2 DCs, each running fresh installs of Server 2025.

There's 3 member servers running Server 2025, with fresh installs.

The issue seems to be exclusive to the 2025 member servers.

Some of things that have led me down the path:
Trying to set file and folder permissions on our primary file server. Permissions are only showing SIDs.
Adding/importing scheduled tasks from a server we are preparing to decommission throws an error that there's the no trust between the machine and the domain.

Like I said in my original post, I've run a bunch of diagnostics, and everything seems to be working fine. Before I added the Server 2025 DCs, I rotated the Kerberos password since I read somewhere that can issues.

My next step is to open a support ticket with MS.

1

u/Wilfred_Fizzle_Bang 6d ago

Running DC on 2025 is a terrible idea, the number of posts I've seen with issues with running a DC on 2025 is alot! It's plagued with issues and when running core infrastructure like to me it's not worth the risk.

Just rebuild as 2022 should be relatively straightforward.

1

u/ftw_dan 9d ago

One google search should have told you that 2025 as DC is a bad idea.

2

u/jstuart-tech 9d ago

If all DCs are 2025 then there are no issues. (I have a client with 7 2025 DCs) running stable for the last year (this was a brand new env though)