1,924 questions with Windows for business | Windows Server | Devices and deployment | Configure application groups tags
Trojan:Win32/Wacatac.B!ml >> Microsoft Safety Scanner found several infected files during scan but end result shows nothing
Windows Defender has detected the Trojan:Win32/Wacatac.B!ml I started the scan with MS Safety Scanner, it took about 24 hours to complete the full scan. During the scan, I can see that it shows about 250 infected files. However, the result, shows that…
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups
Using gMSA for replacing the Task Scheduler service account?
What steps should I follow to change the current Task Scheduler service account from using the regular AD Account in the format of CORP\service.account to a gMSA? When I try to change it manually by double-clicking on the task, it prompts for the…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups

Is Microsoft downplaying support for ECC certificates?
Hi folks, does anyone have any insight into this statement Microsoft's trusted root program requirements page that was updated in Feb? Signatures using elliptical curve cryptography (ECC), such as ECDSA, are not supported in Windows and newer Windows…
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
Online Responder (OCSP) request with hashAlgorithm SHA256, response unauthorized (6)
Hi! We faced with the problem of OCSP role on Windows Server 2019 (I also tried to rise the same role on our test Windows Server 2025 with the same result). We started updating our old Cisco devices to a new firmware and our remote vpn spokes lost their…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
Protected Users AD security group issue with remote server access using the IP address or alias name?
After adding to the Protected Users AD group, I am unable to access the remote server using the IP address or alias name. Protected Users Security Group | Microsoft Learn Guidance about how to configure protected accounts | Microsoft Learn Now people…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups

AD assessment tools
Are there any recommended reporting tools that you can use to scan your Active Directory setup and configuration and get a report of problems/risks/non recommended settings to address?
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | Devices and deployment | Configure application groups
The benefits in setting 'Password expiration policy' to 'Set passwords to never expire (recommended)'?
What will be the safeguard or the additional safety control we must deploy when setting the user password never to expired? Because I have seen multiple recommendations from the below sources advising to set the password to never expired. CISA:…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Server | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Entra | Other

Anywhere Access certificate will expire soon - I can't renew it.
Hi. I have a Windows Server 2012r2 that has had Anywhere Access for years. I've recently been getting a warning that "The Anywhere Access certificate will expire soon. You must renew the certificate to continue using Anywhere Access." I…
Windows for business | Windows Server | Devices and deployment | Configure application groups
The local administrator account is disabled when on-premises LAPS is decommissioned and the device is moved to Intune as co-managed, without a corresponding Windows LAPS policy being applied for the same local account
Hi All, I have an on-premises legacy LAPS server managing local administrator passwords for end-user machines. As part of our modernization efforts, I’ve configured Windows LAPS in Intune and transitioned the end-user devices to a co-managed state. After…
Windows for business | Windows Server | Devices and deployment | Configure application groups
How to configure Windows 11 as a local NTP server (works in Windows 10, not in 11)
Hello, I'm trying to configure my Windows 11 Pro machine to act as a local NTP server on my LAN. I followed the same procedure that works perfectly on Windows 10, including: Modifying the…
Windows for business | Windows Server | Devices and deployment | Configure application groups
Security requirements to be considered for Microsoft Data Migration
What specific security requirements should be considered in case of Microsoft O365 and Azure Data Migration between tenants. Is there any specific checklist from Microsoft which can be considered as an initial starting point? Thanks. Regards.
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Intune | Security
Windows for business | Windows Server | Devices and deployment | Configure application groups
Outlook 2024 slows down massively when using remote credential guard
I would like to share some information here that might save one or the other admin who is in charge of Office and/or network security a few gray hairs. Also, I hope some MS office developers read this and ask themselves how this is possible and fix…
Exchange | Exchange Server | Other
Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Windows for business | Windows Server | Devices and deployment | Configure application groups
Microsoft XDR (Defender) - DeviceEvents - ShellLinkCreateFileEvent
Hi everyone, I've been trying to create a hunting query in the Defender portal to identify when a malicious .lnk file is created. I noticed that an interesting event to detect and analyze this is "DeviceEvents --> ShellLinkCreateFileEvent",…
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows Server 2022 - Update Error 0x80073701 for KB5005619
Good day all I have updated several servers from 2019 to 2022, which worked without any problems. But on one server, the message appears in the updates: "There were some issues installing the updates, but we will try again later". If you…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Adding Authority Key Identifier (OID: 2.5.29.35) to CAPolicy.inf in ADCS
The goal is to configure a new Certificate Authority (CA) using Active Directory Certificate Services (ADCS) and add the Authority Key Identifier (AKI) extension to the root certificate generated during CA installation. The AKI needs to match the Subject…
Windows for business | Windows Server | Devices and deployment | Configure application groups
CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability
Hi All https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900 To remediate the vulnerability CVE-2013-3900 is to add the below registry values. [HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config] …
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
Converting Trusted Azure VMs to Standard VMs
I have created a Windows Server VM with Trusted Launch Virtual Machine and am unable to add it to Azure Site Recovery. Is there a way to convert the running VM to a standard VM? Additionally, I am unable to add backups to a standard backup policy.
Azure Backup
Azure Virtual Machines
Azure Site Recovery
Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Windows for business | Windows Server | Devices and deployment | Configure application groups

Open ports are shown as blocked
Hello, I have a question regarding the installation of an Exchange Server 2016. Currently, I am getting error messages at testconnectivity.microsoft.com regarding closed ports: "Testing TCP port 443 on host autodiscover.DOMAIN:TLD to ensure…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Microsoft Defender Antivirus Vs Symantec Endpoint Protection
Hi, We are looking into replace Symantec Endpoint Protection with Microsoft Defender and have some questions. Our environment is as follow 100 servers (Windows Server 2003, 2008 R2, 2012 R2, 2016 and 2019) 100 clients (Windows 7 Ent, Windows…
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Enable Bitlocker On file Server
Hi, Our Security team decides to use BitLocker encryption on file server disks, my question does it supported or not. does the user will be able to access the shared files after enables BitLocker. Thanks
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
