Active Directory

How can we improve Active Directory in Windows Server?

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  1. output Subject Alternative Name extension using certutil -view

    I would like to be able to output the SAN in a certificate with the command CertUtil.

    the cmdlet get-certificate seems to do the job but only for the local store.

    thanks

    1 vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)

      We’ll send you updates on this idea

      0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
    • Active Directory Administrative Center (ADAC) search feature is incomplete

      well, WTH?! ADUC lets you find users, computers, group, printers, shares, etc.

      why on earth the new ADAC is lacking this feature? why don't you have the option to choose primitive object types in ADAC search as you can in ADUC? I know you have LDAP query builder and all that (which is awesome by the way); but shouldn't simple stuff be available and intuitive stuff be as easy as they have always been with newer tools?

      1 vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)

        We’ll send you updates on this idea

        0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
      • ADFS and Claims Rule Language Reference

        we need a comprehensive syntax and semantics reference for Claims Rule Language. I know there are operators besides == ~= EXIST and such, which are not covered here. and this link is by far the most comprehensive which is available:
        http://social.technet.microsoft.com/wiki/contents/articles/4792.understanding-claim-rule-language-in-ad-fs-2-0-higher.aspx

        1 vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)

          We’ll send you updates on this idea

          0 comments  ·  ADFS  ·  Flag idea as inappropriate…  ·  Admin →
        • BUG: 2016 server allows you to create machines with same name

          I added a 2016DC to my 2012 and 2012r2 DCs a couple weeks ago.

          Today I added a new PC into the network.

          The problem is I used the same name as a PC already on the network (shouldn't be an issue Windows always catches this and doesn't allow it).

          AD didn't catch this and actually updated the original PC in AD and did not add a second PC or warn that the name was already in use. If I look at the modified date of the original pc in AD it shows it was modified at the same time…

          1 vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)

            We’ll send you updates on this idea

            2 comments  ·  Domain join  ·  Flag idea as inappropriate…  ·  Admin →
          • Automatic DNS Record Priority via Inter-Site Transport Cost

            Non-Windows Kerberos clients authenticating against AD typically find an AS by querying DNS, e.g. for a SRV record at "_kerberos._tcp.myrealm." Unfortunately, the default query reply does not do a good job of prioritizing the results. In a default configuration, the DNS priority for the results will all be the same. Although there are some workarounds (netmask ordering), these may not be appropriate for all scenarios -- as when the client subnets are in a random order.

            I propose that Windows DNS have an option to return results with a calculated priority based on the inter-site transport cost between the client…

            2 votes
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)

              We’ll send you updates on this idea

              0 comments  ·  Flag idea as inappropriate…  ·  Admin →
            • Dynamic Security Groups

              Managing group memberships has always been a pain, and given the manual nature of managing security groups we tend to just leave them alone and let them multiply like rabbits. It would be awesome if Active Directory would finally after all these years introduce the concept of Security Groups that have dynamic membership based on, well, any other AD Attribute and support logic similar to the new ADFS Access Control rules

              1 vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)

                We’ll send you updates on this idea

                0 comments  ·  Flag idea as inappropriate…  ·  Admin →
              • Allow group managed service Accounts (gMSA) to have a dummy password

                It's 2017 and there's still Server Software (even microsoft's own - like TFS), which is not able to handle gMSAs, because the password field is mandatory.
                Since that software probably uses windows function to sign-in as such a user, it would be nice to have a mechanism, which allowed us to just use a dummy password for such an account - like "groupManaged" or "-" whatever else.

                So perhaps this is possible, that Windows Server introduces a mechanism allowing to type a password in the mandatory password fields, which signalizes the same as an empty password for gMSAs.

                2 votes
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  0 comments  ·  Logon, Passwords  ·  Flag idea as inappropriate…  ·  Admin →
                • WhatIf switch does not work on cmdlet Install-AdcsCertificationAuthority

                  The whatif switch is not working when installing a ADCS with the cmdlet Install-AdcsCertificationAuthority. The cmdlet is executed in full.
                  I blogged about it here:
                  https://mssec.wordpress.com/2016/02/18/installing-ca-via-powershell-whatif-not-working/
                  Jeffery Snover himself asked me on Twitter to submit a bug reort on this, see here:
                  https://twitter.com/jsnover/status/827524167465525249

                  1 vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                  • New-ADuser fails when the path contains brackets.

                    If you have an OU name '1) Accounts' so the whole path is something like:
                    OU=1) Accounts,OU=sitename,DC=companyname,DC=com
                    New-ADUser -path will fail.
                    A workaround is to create the user and then move them later using something like:
                    Get-ADUser -Identity newuser | Move-ADObject -TargetPath OU=1) Accounts,OU=sitename,DC=companyname,DC=com

                    1 vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                    • Get-ADObject LDAP Extended Controls parameter

                      I would like the option to use LDAP Extended Controls with the Get-ADObject cmdlet.

                      As of Server 2016 you can use Get-ADGroup with -ShowMemberTimeToLive to see the TTL for expiring links or Get-ADObject with -IncludeDeletedObjects to include deleted objects.

                      However you can't use Get-ADGroup for Shadow Principals (used for Privileged Access Management) and Get-ADObject doesn't have the ShowMemberTimeToLive parameter.

                      So I suggest adding an ExtendedControls parameter to get Get-ADObject cmdlet, so you can pass the LDAP Extended Control OID you need to it.

                      At the very least add "ShowMemberTimeToLive" to Get-ADObject.

                      LDAP Extended Controls:
                      https://msdn.microsoft.com/en-us/library/cc223320.aspx

                      2 votes
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                      • Show DisplayName and Description in the Members tab on a group in ADUC

                        When viewing a group membership in ADUC, it would be extremely helpful to show additional columns like DisplayName and Description directly instead of having to open up each CN when our usernames/CN's are not friendly when they come from an enterprise provisioning system. The ability to directly see an account type, and name of user would allow us to remove people immediately without recursion.

                        1 vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                        • Additional Information on what features require Windows Server 2016 Functional Level or Schema 87. Not currently documented.

                          Documentation is missing on what features require the Windows Server 2016 Functional Level and/or Schema Version 87.
                          - I found one mention in an Ignite presentation that said Windows Hello for Business requires Windows Server 2016 Functional Level.
                          -Conflicting old info on non-MS sites indicate Bastion forest needs to be Server 2016, but TechNet says 2012 R2 okay.

                          This link for 2016 Functional Level provides insufficient information.
                          https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-ds/windows-server-2016-functional-levels

                          5 votes
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                          • ADFS should support SQL Azure

                            Please add support to use SQL Azure as DB. Would open up some easy HA scenario deployments for ADFS.

                            1 vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)

                              We’ll send you updates on this idea

                              0 comments  ·  ADFS  ·  Flag idea as inappropriate…  ·  Admin →
                            • AD FS should not require Domain Admin privileges

                              Right now in Windows Server 2012 R2 you are required to run present Domain Admin credentials while installing. This is not an option when AD FS and AD DS are supported by separate teams - it exposes domain admin credentials to persons which are not allowed to know them.
                              This was not a case for AD FS 2.0 - please remove the need of DA privileges to be entered at AD FS server.

                              10 votes
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)

                                We’ll send you updates on this idea

                                0 comments  ·  ADFS  ·  Flag idea as inappropriate…  ·  Admin →
                              • join domain

                                Add the setting of ACL for domain join to "New-ADComputer" cmdlet.

                                In MMC it is possible to create an Computer AD Account and set "The following user or group can join this computer to a domain"

                                Would be nice to have it in New-ADComputer

                                4 votes
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)

                                  We’ll send you updates on this idea

                                  0 comments  ·  ADFS  ·  Flag idea as inappropriate…  ·  Admin →
                                • AGPM status icons and requester feedback

                                  AGPM is a great tool for GPO management but I think it's missing some functionality.
                                  When working in the controlled GPO section you have icon showing if a GPO it's checked out. Would be good to see more status icons showing these states: deployed, checked out, modified after deployment.
                                  Also it would be nice if the requester of a GPO action can get mail notification back when it's done or rejected.

                                  4 votes
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)

                                    We’ll send you updates on this idea

                                    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                                  • get-aduser error on date attribute

                                    The get-aduser command fails when attempting to retrieve an attribute that contains a date value in the year 2000 with the following error message:

                                    Get-ADUser : Year, Month, and Day parameters describe and un-representable DateTime.

                                    Example:

                                    Get-ADUser -Identity <common-name> -Properties <SomeDateField>

                                    where the string <SomeDateField> represents an attribute that contains a human readable date, and not an offset value.

                                    1 vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)

                                      We’ll send you updates on this idea

                                      0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Bug - Active Directory Administrative Center Global Search

                                      When double-clicking on a search result in "Global Search", the item that opens is the previously selected item, not the one that is double-clicked.

                                      Steps to reproduce: Open ADAC, enter a value in global search that will get more than one result, for example "domain". This will give a list of results, the top one will be selected. Double-click on any result that is not the selected one.

                                      Result: The previously selected item opens
                                      Expected result: The double-clicked item opens

                                      11 votes
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)

                                        We’ll send you updates on this idea

                                        4 comments  ·  Bug  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Managed Service Accounts in Active Directory Administrative Center

                                        I would like to create, view and edit Managed Service Accounts from Active Directory Administrative Center.

                                        13 votes
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)

                                          We’ll send you updates on this idea

                                          0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Get-ADPrincipalGroupMembership Raises Error if any Group Name has the "/" character

                                          The Get-ADPrincipalGroupMembership PowerShell cmdlet raises an error if any of the groups retrieved has the "/" character in the common name. Error message is "The server was unable to process the request due to an internal error", followed by instructions to get more details or turn on tracing.

                                          For example, if user "cn=Frank Madison,ou=Sales,ou=West,dc=MyDomain,dc=com" is a member of the group "cn=East/West,ou=Admin,dc=MyDomain,dc=com", then the following raises the error:

                                          Get-ADPrincipalGroupMembership -Identity "cn=Frank Madison,ou=Sales,ou=West,dc=MyDomain,dc=com"

                                          This issue is similar to the one reported here, where the "/" character is in the name of the user, not the group:
                                          https://windowsserver.uservoice.com/forums/301869-powershell/suggestions/11088447-get-adprincipalgroupmembership-error-with-in-p

                                          2 votes
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)

                                            We’ll send you updates on this idea

                                            2 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3
                                          • Don't see your idea?

                                          Feedback and Knowledge Base