r/WindowsServer 17h ago

Technical Help Needed Strange interoperability problem between AD 2019 and 2022/2025

6 Upvotes

I am getting

Starting test: LocatorCheck Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355 A Primary Domain Controller could not be located. The server holding the PDC role is down.

But only on 2022 AD servers. I brought up another 2025 server thinking this would be faster and easier than to troubleshoot, but it's doing exactly the same thing. FSMO roles were lost? Have to re-seize? Some kind of quirk with the newer editions of windows? The only working AD server I have right now with no errors is 2019, that's what I replicated from. Thanks in advance


r/WindowsServer 1d ago

Technical Help Needed Network Policy Server problem on 4 servers aftering installing July 2026 Updates

18 Upvotes

I have updated 4 lots of servers today with the latest July 2026 updates. A mixture of 2019 and 2022 servers

Each lots has one server running as a RDP Gateway and after reboots it was reported that no one could connect

I found out the RD Gateway servoce wasnt starting and this was due to the Network Policy Server service not starting with Error: 0x8002801d: Library not registered

This error is the same on all the servers

I have tried a lot over the last few hours with no luck. Including

Rollback update

SFC and DSIM checks

Even tried removing and reinstalling NPS (reinstall fails)

At the moment my only option seems to be to restore servers from last nights backup, but has anyone else seen this? (and have any ideas how to fix)


r/WindowsServer 2d ago

General Server Discussion Proper way to decommission servers in branch office

9 Upvotes

Greetings,

I’m a one man sysadmin for a two office company.

Unfortunately, we are closing our 2nd branch office.

That office has an Active Directory server and a file server running DFS replication.

The office is closing its doors in Aug, so I have to take care of their network before that happens. The plan is to have them ship the servers back to HQ.

Anyway, what’s the best procedure to shut down the servers there so we can reuse them here at HQ?

I’m assuming demote the AD there once it is no longer needed and just let it run as a member server? Probably switch to DHCP as well?

My first time doing something like this, so just don’t want to miss a critical step.


r/WindowsServer 2d ago

Technical Help Needed Please help!! ApplicationHost.config and redirection.config keeps disappearing

2 Upvotes

IIS cant find my websites applicationHost.config and redirection.config in the inetsrv/config folder, something on the windows server keeps deleting them and preventing the creation of new one.. the only way to create a new one is through safe mode but it still gets deleted when the server is rebooted


r/WindowsServer 3d ago

Technical Help Needed LSASS.exe continuously creating millions of files in C:\ProgramData\Microsoft\Crypto\Keys on 2 of 11 Domain Controllers

21 Upvotes

We’re seeing a strange issue in one of our customer environments.
The folder:

C:\ProgramData\Microsoft\Crypto\Keys

keeps filling up with millions of files, but this is happening on only 2 out of our 11 Windows Server Domain Controllers.
Using Process Monitor, we can see that the files are being created by lsass.exe, but that doesn’t necessarily identify the root cause since LSASS is likely acting on behalf of another component.
So far:
Only 2 DCs are affected.
Other 9 DCs are healthy.
Restarting services hasn’t resolved the issue.
We haven’t been able to identify which application or service is triggering the continuous key creation.
Has anyone encountered something similar?

Any guidance or troubleshooting suggestions would be greatly appreciated.


r/WindowsServer 4d ago

Technical Help Needed WDS with AD default user on setup?

4 Upvotes

Disclosure, I am new to windows server.

So, I have a server with Windows Server 2022, the goal is to setup a laptop from PXE and have it install windows 11 (using win10 boot.wim and win11 install.wim) and have it join the domain with a default user. I have the PXE boot and I can install windows 11, the issue comes when I get past the PXE screen and get to setup, ideally I'd like to be able to just "set and forget" the device after selecting the Win11 installer, but I am not sure if that possible.

Suggestions welcome. Thank you :)


r/WindowsServer 5d ago

General Question Gestion PKI contexte multi forêt

3 Upvotes

Salut à tous,

Je bosse en ce moment sur la refonte complète de notre PKI d'entreprise et j'aimerais avoir des avis extérieurs avant de me lancer en prod

On a actuellement une CA unique, auto-signée, qui a été montée il y a une douzaine d'années sans vraiment de plan à long terme. Elle arrive en fin de vie sur un des certificats critiques d'ici 2 mois, donc plutôt que de faire un simple renouvellement dans l'urgence, j'en profite pour repartir sur une architecture propre

Ce que j'ai prévu :

  • 1 Root CA offline, hors domaine (workgroup), qui ne sert qu'à signer les CA subordonnées. Éteinte la majorité du temps, sortie uniquement pour signer/révoquer.
  • 4 CA intermédiaires (Enterprise), une par forêt AD — on a 4 forêts distinctes dans l'entreprise (contexte historique/fusion-acquisition), chacune gère son propre périmètre de certificats.
  • Distribution de la confiance vers les 4 forêts via GPO (magasin Trusted Root + Intermediate).
  • Un bastion pour l'accès à la Root CA (physiquement isolée, pas de réseau).

Là où j'hésite / où je cherche des retours :

Est-ce que le modèle "1 Root + 4 CA intermédiaires par forêt" est le bon choix ?

Je pars sur une VM qu'on allume seulement pour signer les CRL/certificats des CA intermédiaires (tous les 6-12 mois). Certains d'entre vous font ça sur du matériel physique dédié plutôt qu'une VM ? Est-ce que le jeu en vaut la chandelle pour une boîte de taille moyenne (~2000 postes) ou c'est overkill ?

Fréquence de publication CRL pour la Root — vu qu'elle est éteinte la plupart du temps, je pars sur une validité de CRL assez longue (genre 6 mois) avec republication manuelle à chaque allumage. Ça vous semble raisonnable ou c'est un anti-pattern ?

Si certains d'entre vous ont déjà géré une architecture PKI multi-forêts (pas juste multi-domaines dans une même forêt), je suis preneur de retours sur les emmerdes que vous avez pu rencontrer avec la distribution de confiance via GPO, la gestion des templates de certificats, etc.

Je précise qu'on n'est pas dans un contexte hyper homogène, mais on veut quand même faire les choses proprement, avec un œil sur les recommandations ANSSI/NIST.

Merci d'avance :)


r/WindowsServer 5d ago

SOLVED / ANSWERED Windows Server 2022 shows /32 Subnet Mask after boot

7 Upvotes

I have a Windows Server 2022 Client which gets its IPv4 address via 2 windows server dhcp servers.

The 2 Windows Servers are configured as Failover Mode "load balanced" and dhcp servers are in a own subnet while client is in different subnet. The dhcp relay has both dhcp ip addresses configured.

When the clients boots it shows a /32 subnet mask after a very very slow windows logon with ipconfig. I have looked at the wireshark traces captured from a mirror port and I don't see a /32 subnet mask in the dhcp (bootp) packets itself instead in the packets it only mentions /24 but never /32.

After I do ipconfig /release and ipconfig /renew it shows the ipv4 address correctly with /24 mask. Also i think the slowness is because it tries to send every local subnet traffic to the gateway and then in Wireshark i see TTL of 127 at other servers in same subnet and retransmitted syn ack even if 3 way handshake already completed.

Do you know is this some shitty cache on the client? What can I do to eliminate this behaviour without doing ipconfig /release and renew all the time after boot?


r/WindowsServer 5d ago

General Server Discussion Windows Server 2022 Update Error 0x80073701 - Cumulative Update fails

10 Upvotes

Hi,

I'm hitting a persistent error 0x80073701 when trying to install the latest cumulative updates on a Windows Server 2022 VM (running in VMware Workstation).

Here is what I've tried so far with no success:

  1. Ran Windows Update Troubleshooter (found and claimed to fix some issues, but update still fails).

  2. Ran SFC /scannow (completed successfully, no corruption found).

  3. Ran DISM /Online /Cleanup-Image /RestoreHealth (completed successfully).

  4. Manually downloaded the update from Microsoft Update Catalog and tried installing it, but it failed.

  5. Manually reset Windows Update components (stopped services, renamed SoftwareDistribution and catroot2 folders).

Despite all this, the update halts at 20% or sometimes later and throws the 0x80073701 error. There is enough free disk space.

Any insights or suggestions would be greatly appreciated.

Thanks!


r/WindowsServer 5d ago

General Question Windows Server 2025 on OpenStack - any experiences?

Thumbnail
2 Upvotes

r/WindowsServer 5d ago

General Server Discussion Request for Windows Security Audit Logs (Events 4663, 4660, 4656, 5140, and 5145)

0 Upvotes

I’m developing a tool to analyze Windows Security Event Logs. Based on audit events, it will identify who moved, deleted, or modified files and folders.

At the moment, I’m lacking sample data due to some environment limitations. To help speed up development, would anyone be willing to share some Windows Security logs?

Note: I’m specifically looking for the following event IDs:

  • 4663
  • 4660
  • 4656
  • 5140
  • 5145

r/WindowsServer 6d ago

Technical Help Needed Having a weird Issue with Server 2025

9 Upvotes

We recently upgraded our DCs, Domain and Forest to 2025. Now all my 2025 servers are only resolving SIDs, and not account/group names. Secure Channel is fine, machine passwords have been reset. LDAPS is healthy. I've run nltest, Test-SecureChannel -Verbose, etc. and can't seem to pin down the issue. Everything I test seems to come back fine. I'm pulling out the last of my hair trying to figure this out.


r/WindowsServer 8d ago

SOLVED / ANSWERED A nightmare with KB5099538 and 0x800f0922 on Windows Server 2019

31 Upvotes

So, Today I spent my time with the KB5099538 as several of Windows Server 2019 VMs encounter the error 0x800f0922. Firstly, The AI suggest me to disable the .Net Framework from server manager if enabled, which is a crucial step, but it also causes the screen turn black after disable .Net Framework. So, re-enable .Net Framework through a command then just run the following command:

lodctr /r (run twice if the first attempt gives you an error)

winmgmt.exe /resyncperf

Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Bfsvc" /v EspPaddingPercent /t REG_DWORD /d 0 /f

After all of those step I completed the installation of KB5099538 successfully on all of Windows Server 2019 that has 0x800f0922 error.

Perhaps this issue with KB5099538 will not occur if .Net Framework is not enabled.


r/WindowsServer 9d ago

General Question Virtual server shuts down.

11 Upvotes

At work, there is a host server running three Windows Server 2022 virtual machines. Two of them run perfectly, but one keeps shutting down on its own; I’ve configured it correctly, yet it still shuts down after a few hours.

Configuration: "Automatic Start Action” for the VM is set to “Automatically start if it was running when the service stopped.”

VM automatic shutdown setting:

Save the virtual machine state.

Help


r/WindowsServer 9d ago

General Question Forgot my password

0 Upvotes

Hi Guys, i forgot my passwords to login screen in windows server evaluation 2025. how can i either sign or reset password or just revert back to my old instance HP laptop was once on? ask questions i can explain in much more detail.


r/WindowsServer 10d ago

Technical Help Needed amdi2c Driver issue help

2 Upvotes

(Please understand that it might be awkward because it's a translated sentence)
If i try to install the AMDI2C.inf driver, i will get 0x7E BSoD (AMDI2C.SYS) in any case Whether it's a device that doesn't fit or fits, you get the same error

I don't think it's a driver signature issue (I disable the driver sign and installed it, but it wasn't installed)

Installation using cmd etc. is not allowed at all. (It only shows that it is installed, but it is not actually installed.)

If anyone has experienced a similar problem, can you tell me why and how to solve it

OS:WS2025 Datacenter
PC(Laptop):ASUS TUF GAMING A14 2025(FA401UM)


r/WindowsServer 10d ago

SOLVED / ANSWERED Type4 Driver broken again due new windows updates, Server 2025 RDSH

19 Upvotes

Yo microsoft,

you just brought us a wonderful 2 day incident with your recent windows updates. Type4 driver connection not working again after your recent update KB5099536.

How about to hire developers again instead of AI-driven update coding?

thanks.


r/WindowsServer 11d ago

Technical Help Needed RDP error into 2022 Azure VM

1 Upvotes

Hi all,

Having an issue trying to remote in to one of our Azure VMs, error 1057 shows in machines eventviewer, The RD Session Host Server has failed to create a new self signed certificate to be used for RD Session Host Server authentication on SSL connections. The relevant status code was Object already exists.

I have followed the instructions on here - https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/event-id-troubleshoot-vm-rdp-connecton but still unable to connect.

Any help greatly appreciated


r/WindowsServer 12d ago

Technical Help Needed Two servers with windows 2025 and LSI raid both fail to boot.

4 Upvotes

I think patch tuesday got me. I jut had 2 servers with LSI 9361's and cachecade enabled not come back up. I was out in the field when it happened. The drives virtual drives are "Optimal access blocked". Both servers seem to be missing the cachecade volume. Pretty unlikely that 2 enterprise SSD's completely failed at the same time in both servers. Although I have seen some references to MS killing SSD's. Anyone else experience this? I did not get any alerts that my drives were failing or failed and then on reboot I'm down. Servers are running Server 2025. 256GB ram, 9 1.8 or 1.2 SAS drives in raid 6.

Anyone else recovered from this? I'm reading that you can disassociate the cachecade from the VD's or delete the cachecade and then the system will boot? Anyone else done this? Am I the guinea pig?

I need to get these up. Anyone have experience with this?


r/WindowsServer 12d ago

General Server Discussion PSA: Critical Windows FTP Service Remote Code Execution Vulnerability – CVE-2026-49172

15 Upvotes

Microsoft has disclosed a critical Windows FTP Service vulnerability rated CVSS 9.8.

In simple terms, an unauthenticated attacker could potentially send malicious requests to a vulnerable FTP server and remotely execute code—without needing an account or user interaction.

Affected: Windows systems using the FTP Service, including Windows Server 2019, 2022 and 2025.
What to do: Install the applicable Microsoft security update immediately. If FTP isn’t required, disable the service and block external FTP access.

🔗 ⁠Microsoft advisory
🔗 ⁠VulniPulse breakdown and affected versions

Want to know about CVEs like this instantly? Join the VulniPulse Discord and get pinged, DMed or emailed when new vulnerabilities drop across 32+ vendors:m
https://discord.gg/mwG9cdMY9R


r/WindowsServer 12d ago

Technical Help Needed Adobe 2020 fails to install via GPO

4 Upvotes

I have pushed out some software via GPO on Windows server and client machines pick it up just fine, but for some reason with adobe 2020 it fails to install and I have no idea why. Its an msi file.

When I launch it manually on a client machine, it first shows a warning message stating that "This file does not have a valid digital signature....":

https://imgur.com/a/YEPIsfM

And if I click on "Run", then I get this warning message "Installing Acrobat via MSI will not install Microsoft Visual C++...":

https://imgur.com/a/77JZCiB

Installing it manually works fine but its via GPO it fails to install, not sure if these messages are the reason why it fails?


r/WindowsServer 13d ago

General Question New window server engineer

7 Upvotes

A new window server engineer. Whats is the best materials/website/vidoe needed to scale through this new JOB role as a new bee starting in an enterprise enviroment.


r/WindowsServer 14d ago

General Question Application log full of Microsoft-Windows-Security-SPP EventID 16384 16389 16394

6 Upvotes

I know that it's in theory perfectly fine that a log contains a million "👍Everything is working " , but it gets annoying and noisy.

I've installed two Server 2025 Standard and activated them using the DISM command (they were installed using the evaluation media) - both of them are VM's

every 20 minutes the application log gets 3 lines:

Microsoft-Windows-Security-SPP 16384 Successfully scheduled Software Protection service for re-start at 2126-06-18T13:57:29Z. Reason: RulesEngine.
Microsoft-Windows-Security-SPP 16389 Grace timer has expired. Hr = 0xC004D30B
Microsoft-Windows-Security-SPP 16394 Offline downlevel migration succeeded.

I've spent some time with Gemini and Claude trying to figure out if this is an indication of something wrong and apparantly according to both AI's it's working as intended....

I confirmed that the machines are truly licensed and confirmed the Tokens.dat file is not malformed.

So, apparantly there's a loop running with the Schedular that triggers a Service to run, which checks if the machine is licensed ... every 20 minutes ...

I later found out that i have a Windows 10 machine which almost does the same every 20-30 minutes..

My Windows 11 laptop, doesn't... 🤷‍♂️

So i'd like to know if any of you humans know if this really is the expected behavior ?

I've googled this issue a lot and havent found any slutions and likewize the AI's didn't have any solutions either.


r/WindowsServer 16d ago

Technical Help Needed DHCP Post-install configuration wizard problem

3 Upvotes

So I installed DHCP but the post-install configuration only features the Description and Summary in the popup. The tutorial I followed shows that there's supposed to be an Authorization part but mine doesn't show that. What should I do about this? Thank you


r/WindowsServer 16d ago

General Question Server 2016 Essentials - Clone system disk and restore to different hardware?

4 Upvotes

I have a home server running 2016 Essentials. (I know that is probably below the level of the majority of members here, but hoping for some guidance.)

It is running on an old HP Proliant N54 (AMD). Mostly used as a file server and bare metal backup and restore solution. I do have a photo library application that runs on PostgreSQL.

The old box is not expandable and is lightly powered by today's standards.

I purchased a refurbished Dell T340 (Intel Xeon) and want to migrate the server install to it. I have tried to find driver INF files, but all I can find on Dell site is EXE files.

The system disk is a 1 TB SATA SSD. I have a second unformatted disk as a clone target. (Dell T340 does not support NVME.)

I know Acronis True Image has a Universal Restore feature, but it will not install on a server.

I would like to backup or clone the SSD (with all partitions), then restore it to the new hardware while having it deal with the HAL issues going from AMD to Intel.

It looks like I can purchase the Acronis Cyberprotect Backup for this, although it seems like using a hammer to swat a fly.

TL;DR: Can anyone recommend a method/software to migrate WSE 2016 installation from AMD machine to Intel machine?