Ask a question

Jesper Dahlstrøm

Subdomain in Dmarc report

Hi all, Our dmarc reports sometimes shows our subdomain and this leads to failed DKIM and SPF. We do not want to send out mails from name@sub.domain.dk NOTE: the subdomain applied is actually our exchange 2016 FQDN. example:           Our PUBLIC IP       2               none         fail         fail           ...


Jesper Dahlstrøm asked 05/18/2020 07:08
Eugene Palmer

WSE 2016 to 2019 Standard, SYSvol_DFSR?

Hi, At step 17 there is a statement for the sysvol location, C:\Windows\SYSVOL, but on the WSE 2016 source it has been moved to c:\WIndows\SYSVOL_DFSR because there was a branch office and we were using DFSR between two servers.  Is this location at this step for the SOURCE or DESTINATION?   SYSvol replication on the source has tombstoned out and is stale, but otherwise shows ok. I think this is for the Destination, but just checking.


Eugene Palmer asked 05/13/2020 02:17
Eugene Palmer

What might be important to consider when migrating while the entire office is working remotely?

During this Shelter-In-Place time when there are a couple dozen remote workers madly pounding away over remote pathways, at what point in a migration from WSE 2016 to 2019 will an intervention or other action be required to reconnect them to a new server.  I have a hard time believing this will all go so smoothly they will not need to be dis-connected/reconnected.  Folder Redirection and other things look tricky.  Plus, everyone is standard users so no remote admin commands will work, even with a remote session with GoToMeeting or such. I'll read on, but thought I'd ...


Eugene Palmer asked 05/13/2020 02:30
Tim Burgess

WSE 2016 , error connectng to VPN " The certificte's CN name does not match the passed value"

Since lockdown we have been  using the VPN for home workers. Recently it's stopped working alltogether  ( i expect due to a microsoft update ) Usually we repair the VPN from the Server essentials dashboard and it starts working again This is now broken, no reboot or repair has worked. The VPN is configured for SSTP. The connection is fine, the error is certificate based which is where i get stuck. The error being as per title .. "The certificte's CN name does not match the passed value" as it is WSE2016 there is no routing ...


Tim Burgess asked 05/11/2020 14:52
Harlan Lax

Best way to update SBS 2011

I took over an SBS 2011 server that hasn't been updated in over a year.  I am migrating them to Windows 2019 and need to do updates before migration. What is the best way to update the server?  Should I do Windows Update or just download the latest from Microsoft or some other method?


Harlan Lax asked 05/06/2020 17:49
Andrew Stefaniuk

Exchange 2019 & Web Server Internal IP Address/Internal Network Name Disclosure Vulnerability

Hello Group; below are the results of an audit of my newly migrated Exchange 2013 to 2019 as per the guide (Thanks Mariette, Great work) but now I'm leaking my internal IP address information both in email headers and TCP Get requests. It has me thinking about what is disclosed in the below response header and a need to tighten the disclosed information that results with the default install of IIS when installing Exchange as per the guide, like seeing the IIS version, the network machine name, and the private IP address. I see there is and extension ...


Andrew Stefaniuk asked 04/30/2020 13:41
Alexandre Michel

Where is the SSTP VPN actually configured when using the "Windows Essential Experience" on a Server 2016 Standard?

Hi I am curious to find out where the SSL VPN is actually configured when using the "Windows Essential Expereince" I looked for RRAS, but can't find it. So what is running this VPN? Alex  


Alexandre Michel asked 04/13/2020 09:10
Frank Cifelli

Migration SBS2001 to S2019 - No SYSVOL or NETLOGON

I was following through the migration guide for SBS2011 to Server 2019 ( https://server-essentials.com/support/migrate-sbs-2011-to-windows-server-2019# ) and then under Section 7 Step 21 is to verify that there is a SYSVOL and NETLOGON share on the 2019 server and unfortunately they are not there. How do I resolve this to continue the migration? Thanks for your help.


Frank Cifelli asked 04/26/2020 21:53
Allen Stone

error message recived when attempting to integrate Windows Server 2012 R2 Essentials with Office 365 and DNS warning message

Hello All: I am hoping that someone can help me fix a couple of problems that I am having with integrating Windows Server 2012 R2 with Office 365 and starting the DNS service on my server. When I look at the DNS section of the server, I get the following warning: The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS data might not yet be ...


Allen Stone asked 04/27/2020 04:11
Kile Young

Post SBS 2008 Migration to Windows Server 2016 Standard or Datacenter

Hello, How do I delete the SBS 2008 OUs after completing the migration?  I've tried to change the attribute that restricts the ability to delete these but receive an error.  See the attached screenshot.   -Kile Young    


Kile Young asked 04/26/2020 23:28
tony richardson

SBS2008 to Server 2019 issue when promoting the server 2019 to domain controller

When running the command to promote the server 2019 to domain controller I get the following error: PS C:\Users\Administrator> Install-ADDSDomainController -NoGlobalCatalog:$false -CreateDnsDelegation:$false -CriticalReplicationOnly:$false -DatabasePath "C:\Windows\NTDS" -DomainName $currentDomain -InstallDns:$true -LogPath "C:\Windows\NTDS" -NoRebootOnCompletion:$true -SysvolPath "C:\Windows\SYSVOL" -credential $cred -Force:$true -Confirm:$false -SafeModeAdministratorPassword (ConvertTo-SecureString 'h00dsEnd!' -AsPlainText -Force) WARNING: Windows Server 2019 domain controllers have a default for the security setting named "Allow cryptography algorithms compatible with Windows NT 4.0" that prevents weaker cryptography algorithms when establishing security channel sessions. For more information about this setting, see Knowledge Base article 942564 (http://go.microsoft.com/fwlink/?LinkId=104751). Install-ADDSDomainController : Verification of prerequisites for Domain Controller promotion ...


tony richardson asked 07/02/2019 15:12
BRIAN BURNETT

Windows 10 clients taking two plus minutes to boot after AD migration from S2008 to S2019

Performed AD migration from Server 2008 to Server 2019 Essentials.   Windows 10 1809 and Windows 10 1909 clients are now taking two+ minutes to boot up.   They go though post and then get stuck at loading screen (throbber) spinning for two minutes, then bring up login screen and generally behave as expected.   These computers used to get to the login screen in 15 seconds, so it's a very noticeable change.  It's the same if it's fresh boot or reboot.   Anyone seen this and figured out a fix/workaround? Old AD server is completely unjoined and removed from AD/shutdown. ...


BRIAN BURNETT asked 04/21/2020 17:06
John Nork

Anywhere Access Questions

We have been using Anywhere Access on a Windows Server 2012 R2 Essentials system for years without problems.  We recently had a series of disconnection problems, which were traced back to our ten-year old Comcast gateway/router.  Comcast has replaced the old router with a new model (Cisco DPC3939B).  Having had some problems in the past with the Essentials Remote Web Access system, I want to be careful and implement the replacement router correctly. First of all, which option should I select in Anywhere Access (new installation or repair)?  Can I use the Microsoft supplied domain name that ...


John Nork asked 04/20/2020 16:19
Matt Farst

Server Essentials 2016 cannot connect to O365

Hello, I am new to this community. Thus far I have it to be extremely helpful. Thanks to all who contribute to the excellent content. I have been out of the IT industry for about 10 years, and as the co-owner of a small business, I now am the default IT person for our company. Now to my question: I am sure this has been asked a thousand times, but,,,,, We recently acquired our first server. We are running Windows Server Essentials 2016. I have tried every tip I could find yet I am still ...


Matt Farst asked 04/18/2020 01:16
John Nork

Remote Web Access - Reconnecting, the Connection Has Been Lost

We have been able to connect to an Essentials 2012 R2 network without problem for a quite some time.  Today, however, when the client users tried to connect, they have all gotten the message "Reconnecting, the connection has been lost."  RWA then attempts to reconnect, and the message box shows a counter going up in seconds.  The connection is reset, then then the whole process occurs again (i.e., the connection is lost, then re-established, etc.).  I tried this on a connection to their server and had the same results.   Any suggestions will be greatly appreciated.  With the ...


John Nork asked 04/14/2020 15:30
Art Saffran

How can Mac (OS/X) computers connect to Server 2016 Essentials VPN?

Clients working remotely with their Macs are trying to connect to the Server 2016 Essentials VPN. Windows 10 computers work fine. The Mac users need a Shared Secret. I don't know what that is because it's not how the remote access services were set up in Essentials and the shared secret is not needed for Windows computers. Is there a way for Macs to connect to the VPN? Thanks. --Art


Art Saffran asked 04/14/2020 14:17
DigiVie Communications

Exchange 2016-2019 404 errors after 2019 install

Hi Mariette, After getting Exchange 2019 installed, I'm unable to move on the step 8 (checking permissions) as I'm getting 404 errors for https://localhost/ecp/?ExchClientVer=15 (or the /owa page). Services are all running. Running Exchange Powershell errors with the following, and then connects to the 2016 exchange. I've checked the Exchange install logs, and it shows the install was successful. Any tips on what to look for? David   VERBOSE: Connecting to DVC-EXCH2019.dvc.local. New-PSSession : [dvc-exch2019.dvc.local] Connecting to remote server dvc-exch2019.dvc.local failed with the following error message : The client cannot ...


DigiVie Communications asked 04/11/2020 16:31
Helio Perlman

Add existing folders to Essentials Server 2012 R2 Experience Role

Hi, Have a domain network and a file server member. Added one Server 2012R2 standard member server with Essentials Experience role to give the users web access. But when I try to add File Server Shares to Essentials Storage tab, it mess with permissions. The dashboard list all users with the read or read/write options and at the end add all users to the security tab off the folder. I use mostly groups on security tab. Are there some way to deal with folders on Essentials using PowerShell? Thanks 


Helio Perlman asked 04/01/2020 02:22
Michael Stoffel

Computers are all marked as removed under WSE Dashboard

All of the computers are marked as removed under the WSE dashboard. All of the client connectors are lit up green and everything is functioning like it should, except Remote Web Access. Attempting to reinstall the client connector lists that the server is not available, but it is.  One thing worth mentioning is that when restarting the server, ADCS does not start on its own even though it is set to. It has to be manually started. Can you think of anything I can do to troubleshoot this? No computers are showing up under the devices ...


Michael Stoffel asked 03/30/2020 19:51
Benjamin Slivka

Cleaning up (deleting, moving) archaic SBS Active Directory entries?

I've successfully migrated from my 7.7 year old SBS2011 computer to my brand new WS2019E computer. Thanks to your great guide. Now, I started with SBS 4.5 way back in 06/1999. And migrated (using the Microsoft step-by-step instructions) to SBS 2000 in 4/2002, and then to SBS 2003 in 11/2005, and then to SBS 2011 in 6/2012. So I have accumulated 20+ years of Active Directory entries from four versions of SBS. See for example the slivka.local > MyBusiness > Security Groups below. I don't want to risk breaking anything, so I'm not eager to ...


Benjamin Slivka asked 03/29/2020 20:33
Andrew Stefaniuk

421 4.4.2 error after migration from Exchange 2103 to 2019 in an SBS2008 scenario

After migrating from Exchange 2013 to Exchange 2019 in an SBS2008 scenario, I’m finding that we have issues sending emails to two of our clients. The email shows up in the Queue viewer and will continue to retry. However, if I disable the send connector and re-enable, the messages will send. The errors are  421 4.4.2 Connection dropped due to SocketError  or a  421 4.2.1 Unable to connect -> SocketError: Failed to connect. Winsock error code: 10051 Again, it's consistently only two clients' email domains this is occurring on.      Any thoughts? Andrew Stefaniuk


Andrew Stefaniuk asked 03/13/2020 18:18
Benjamin Slivka

How do I remove vestiges of old SBS 2011 Certificate Authority?

I just finished migrating from 7.7 year old SBS2011 box ("DUBAI") to brand new WS2019E box ("HOBART"). I believe I've deleted/turned off the Certificate Authority on DUBAI. BUT when I run the  command "certutil -adca" on HOBART, it still reports DUBAI: CAIsValid: 1   cn = slivka-DUBAI-CA   displayName = slivka-DUBAI-CA   dNSHostName = DUBAI.slivka.local   distinguishedName = CN=slivka-DUBAI-CA,CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=slivka,DC=local   cACertificateDN = CN=slivka-DUBAI-CA CAIsValid: 1   cn = slivka-HOBART-CA   displayName = slivka-HOBART-CA   dNSHostName = hobart.slivka.local   distinguishedName = CN=slivka-HOBART-CA,CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=slivka,DC=local CertUtil: ...


Benjamin Slivka asked 03/28/2020 01:09
Benjamin Slivka

How do I eliminate the automatic connection of Z: to \\sbs2011\USERSHARES\username ?

I've completed all of the required steps for the migration from my 7.7 year old SBS2011 box to my brand new Windows Server 2019 Essential box. One niggling problem: When I login to a laptop -- or even the WS2019E box -- I still get drive Z: connected to \\sbs2011\USERSHARES\ben (my login name). I've hunted around online trying to find an answer, to no avail. I tried hunting around in Active Director and Group Policies, but couldn't find any setting for this. And no amount of Google searching has turned up an explanation or solution. ...


Benjamin Slivka asked 03/28/2020 00:56
Slator Turner

How to print server-essentials community articles?

How can I print the following server-essentials article:  community such as:  " Get a free Let’s Encrypt SSL certificate for Access Anywhere and automatically renew it ."


Slator Turner asked 03/26/2020 16:33
User

Domain Joined Computer does not appear in Server Essentials Dashboard

I am running Windows Server 2012 R2 with Essentials Experience feature. I wish to give one user remote access to her own computer via the RemoteWebAccess website. She can login to the website but no computer show up for her to login to. She is enabled to be able to do this in the essentials dashboard and she is enabled for RWA and VPN . The problem appears to be I cannot select her individual computer from Essentials Dashboard's list of computers because her computer is not in the list.  Her computer is not in Essentials device list ...


User asked 11/09/2018 11:54
Manage notifications