r/WindowsServer 14h ago

General Question Gestion PKI contexte multi forêt

3 Upvotes

Salut à tous,

Je bosse en ce moment sur la refonte complète de notre PKI d'entreprise et j'aimerais avoir des avis extérieurs avant de me lancer en prod

On a actuellement une CA unique, auto-signée, qui a été montée il y a une douzaine d'années sans vraiment de plan à long terme. Elle arrive en fin de vie sur un des certificats critiques d'ici 2 mois, donc plutôt que de faire un simple renouvellement dans l'urgence, j'en profite pour repartir sur une architecture propre

Ce que j'ai prévu :

  • 1 Root CA offline, hors domaine (workgroup), qui ne sert qu'à signer les CA subordonnées. Éteinte la majorité du temps, sortie uniquement pour signer/révoquer.
  • 4 CA intermédiaires (Enterprise), une par forêt AD — on a 4 forêts distinctes dans l'entreprise (contexte historique/fusion-acquisition), chacune gère son propre périmètre de certificats.
  • Distribution de la confiance vers les 4 forêts via GPO (magasin Trusted Root + Intermediate).
  • Un bastion pour l'accès à la Root CA (physiquement isolée, pas de réseau).

Là où j'hésite / où je cherche des retours :

Est-ce que le modèle "1 Root + 4 CA intermédiaires par forêt" est le bon choix ?

Je pars sur une VM qu'on allume seulement pour signer les CRL/certificats des CA intermédiaires (tous les 6-12 mois). Certains d'entre vous font ça sur du matériel physique dédié plutôt qu'une VM ? Est-ce que le jeu en vaut la chandelle pour une boîte de taille moyenne (~2000 postes) ou c'est overkill ?

Fréquence de publication CRL pour la Root — vu qu'elle est éteinte la plupart du temps, je pars sur une validité de CRL assez longue (genre 6 mois) avec republication manuelle à chaque allumage. Ça vous semble raisonnable ou c'est un anti-pattern ?

Si certains d'entre vous ont déjà géré une architecture PKI multi-forêts (pas juste multi-domaines dans une même forêt), je suis preneur de retours sur les emmerdes que vous avez pu rencontrer avec la distribution de confiance via GPO, la gestion des templates de certificats, etc.

Je précise qu'on n'est pas dans un contexte hyper homogène, mais on veut quand même faire les choses proprement, avec un œil sur les recommandations ANSSI/NIST.

Merci d'avance :)


r/WindowsServer 1d ago

Technical Help Needed Windows Server 2022 shows /32 Subnet Mask after boot

8 Upvotes

I have a Windows Server 2022 Client which gets its IPv4 address via 2 windows server dhcp servers.

The 2 Windows Servers are configured as Failover Mode "load balanced" and dhcp servers are in a own subnet while client is in different subnet. The dhcp relay has both dhcp ip addresses configured.

When the clients boots it shows a /32 subnet mask after a very very slow windows logon with ipconfig. I have looked at the wireshark traces captured from a mirror port and I don't see a /32 subnet mask in the dhcp (bootp) packets itself instead in the packets it only mentions /24 but never /32.

After I do ipconfig /release and ipconfig /renew it shows the ipv4 address correctly with /24 mask. Also i think the slowness is because it tries to send every local subnet traffic to the gateway and then in Wireshark i see TTL of 127 at other servers in same subnet and retransmitted syn ack even if 3 way handshake already completed.

Do you know is this some shitty cache on the client? What can I do to eliminate this behaviour without doing ipconfig /release and renew all the time after boot?


r/WindowsServer 1d ago

General Server Discussion Windows Server 2022 Update Error 0x80073701 - Cumulative Update fails

8 Upvotes

Hi,

I'm hitting a persistent error 0x80073701 when trying to install the latest cumulative updates on a Windows Server 2022 VM (running in VMware Workstation).

Here is what I've tried so far with no success:

  1. Ran Windows Update Troubleshooter (found and claimed to fix some issues, but update still fails).

  2. Ran SFC /scannow (completed successfully, no corruption found).

  3. Ran DISM /Online /Cleanup-Image /RestoreHealth (completed successfully).

  4. Manually downloaded the update from Microsoft Update Catalog and tried installing it, but it failed.

  5. Manually reset Windows Update components (stopped services, renamed SoftwareDistribution and catroot2 folders).

Despite all this, the update halts at 20% or sometimes later and throws the 0x80073701 error. There is enough free disk space.

Any insights or suggestions would be greatly appreciated.

Thanks!


r/WindowsServer 1d ago

General Server Discussion Request for Windows Security Audit Logs (Events 4663, 4660, 4656, 5140, and 5145)

0 Upvotes

I’m developing a tool to analyze Windows Security Event Logs. Based on audit events, it will identify who moved, deleted, or modified files and folders.

At the moment, I’m lacking sample data due to some environment limitations. To help speed up development, would anyone be willing to share some Windows Security logs?

Note: I’m specifically looking for the following event IDs:

  • 4663
  • 4660
  • 4656
  • 5140
  • 5145

r/WindowsServer 1d ago

General Question Windows Server 2025 on OpenStack - any experiences?

Thumbnail
2 Upvotes

r/WindowsServer 2d ago

Technical Help Needed Having a weird Issue with Server 2025

9 Upvotes

We recently upgraded our DCs, Domain and Forest to 2025. Now all my 2025 servers are only resolving SIDs, and not account/group names. Secure Channel is fine, machine passwords have been reset. LDAPS is healthy. I've run nltest, Test-SecureChannel -Verbose, etc. and can't seem to pin down the issue. Everything I test seems to come back fine. I'm pulling out the last of my hair trying to figure this out.


r/WindowsServer 4d ago

SOLVED / ANSWERED A nightmare with KB5099538 and 0x800f0922 on Windows Server 2019

37 Upvotes

So, Today I spent my time with the KB5099538 as several of Windows Server 2019 VMs encounter the error 0x800f0922. Firstly, The AI suggest me to disable the .Net Framework from server manager if enabled, which is a crucial step, but it also causes the screen turn black after disable .Net Framework. So, re-enable .Net Framework through a command then just run the following command:

lodctr /r (run twice if the first attempt gives you an error)

winmgmt.exe /resyncperf

Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Bfsvc" /v EspPaddingPercent /t REG_DWORD /d 0 /f

After all of those step I completed the installation of KB5099538 successfully on all of Windows Server 2019 that has 0x800f0922 error.

Perhaps this issue with KB5099538 will not occur if .Net Framework is not enabled.


r/WindowsServer 4d ago

General Question Virtual server shuts down.

11 Upvotes

At work, there is a host server running three Windows Server 2022 virtual machines. Two of them run perfectly, but one keeps shutting down on its own; I’ve configured it correctly, yet it still shuts down after a few hours.

Configuration: "Automatic Start Action” for the VM is set to “Automatically start if it was running when the service stopped.”

VM automatic shutdown setting:

Save the virtual machine state.

Help


r/WindowsServer 4d ago

General Question Forgot my password

0 Upvotes

Hi Guys, i forgot my passwords to login screen in windows server evaluation 2025. how can i either sign or reset password or just revert back to my old instance HP laptop was once on? ask questions i can explain in much more detail.


r/WindowsServer 5d ago

Technical Help Needed amdi2c Driver issue help

2 Upvotes

(Please understand that it might be awkward because it's a translated sentence)
If i try to install the AMDI2C.inf driver, i will get 0x7E BSoD (AMDI2C.SYS) in any case Whether it's a device that doesn't fit or fits, you get the same error

I don't think it's a driver signature issue (I disable the driver sign and installed it, but it wasn't installed)

Installation using cmd etc. is not allowed at all. (It only shows that it is installed, but it is not actually installed.)

If anyone has experienced a similar problem, can you tell me why and how to solve it

OS:WS2025 Datacenter
PC(Laptop):ASUS TUF GAMING A14 2025(FA401UM)


r/WindowsServer 6d ago

SOLVED / ANSWERED Type4 Driver broken again due new windows updates, Server 2025 RDSH

17 Upvotes

Yo microsoft,

you just brought us a wonderful 2 day incident with your recent windows updates. Type4 driver connection not working again after your recent update KB5099536.

How about to hire developers again instead of AI-driven update coding?

thanks.


r/WindowsServer 7d ago

Technical Help Needed RDP error into 2022 Azure VM

1 Upvotes

Hi all,

Having an issue trying to remote in to one of our Azure VMs, error 1057 shows in machines eventviewer, The RD Session Host Server has failed to create a new self signed certificate to be used for RD Session Host Server authentication on SSL connections. The relevant status code was Object already exists.

I have followed the instructions on here - https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/event-id-troubleshoot-vm-rdp-connecton but still unable to connect.

Any help greatly appreciated


r/WindowsServer 7d ago

Technical Help Needed Two servers with windows 2025 and LSI raid both fail to boot.

3 Upvotes

I think patch tuesday got me. I jut had 2 servers with LSI 9361's and cachecade enabled not come back up. I was out in the field when it happened. The drives virtual drives are "Optimal access blocked". Both servers seem to be missing the cachecade volume. Pretty unlikely that 2 enterprise SSD's completely failed at the same time in both servers. Although I have seen some references to MS killing SSD's. Anyone else experience this? I did not get any alerts that my drives were failing or failed and then on reboot I'm down. Servers are running Server 2025. 256GB ram, 9 1.8 or 1.2 SAS drives in raid 6.

Anyone else recovered from this? I'm reading that you can disassociate the cachecade from the VD's or delete the cachecade and then the system will boot? Anyone else done this? Am I the guinea pig?

I need to get these up. Anyone have experience with this?


r/WindowsServer 8d ago

General Server Discussion PSA: Critical Windows FTP Service Remote Code Execution Vulnerability – CVE-2026-49172

15 Upvotes

Microsoft has disclosed a critical Windows FTP Service vulnerability rated CVSS 9.8.

In simple terms, an unauthenticated attacker could potentially send malicious requests to a vulnerable FTP server and remotely execute code—without needing an account or user interaction.

Affected: Windows systems using the FTP Service, including Windows Server 2019, 2022 and 2025.
What to do: Install the applicable Microsoft security update immediately. If FTP isn’t required, disable the service and block external FTP access.

🔗 ⁠Microsoft advisory
🔗 ⁠VulniPulse breakdown and affected versions

Want to know about CVEs like this instantly? Join the VulniPulse Discord and get pinged, DMed or emailed when new vulnerabilities drop across 32+ vendors:m
https://discord.gg/mwG9cdMY9R


r/WindowsServer 8d ago

Technical Help Needed Adobe 2020 fails to install via GPO

2 Upvotes

I have pushed out some software via GPO on Windows server and client machines pick it up just fine, but for some reason with adobe 2020 it fails to install and I have no idea why. Its an msi file.

When I launch it manually on a client machine, it first shows a warning message stating that "This file does not have a valid digital signature....":

https://imgur.com/a/YEPIsfM

And if I click on "Run", then I get this warning message "Installing Acrobat via MSI will not install Microsoft Visual C++...":

https://imgur.com/a/77JZCiB

Installing it manually works fine but its via GPO it fails to install, not sure if these messages are the reason why it fails?


r/WindowsServer 8d ago

General Question New window server engineer

8 Upvotes

A new window server engineer. Whats is the best materials/website/vidoe needed to scale through this new JOB role as a new bee starting in an enterprise enviroment.


r/WindowsServer 10d ago

General Question Application log full of Microsoft-Windows-Security-SPP EventID 16384 16389 16394

6 Upvotes

I know that it's in theory perfectly fine that a log contains a million "👍Everything is working " , but it gets annoying and noisy.

I've installed two Server 2025 Standard and activated them using the DISM command (they were installed using the evaluation media) - both of them are VM's

every 20 minutes the application log gets 3 lines:

Microsoft-Windows-Security-SPP 16384 Successfully scheduled Software Protection service for re-start at 2126-06-18T13:57:29Z. Reason: RulesEngine.
Microsoft-Windows-Security-SPP 16389 Grace timer has expired. Hr = 0xC004D30B
Microsoft-Windows-Security-SPP 16394 Offline downlevel migration succeeded.

I've spent some time with Gemini and Claude trying to figure out if this is an indication of something wrong and apparantly according to both AI's it's working as intended....

I confirmed that the machines are truly licensed and confirmed the Tokens.dat file is not malformed.

So, apparantly there's a loop running with the Schedular that triggers a Service to run, which checks if the machine is licensed ... every 20 minutes ...

I later found out that i have a Windows 10 machine which almost does the same every 20-30 minutes..

My Windows 11 laptop, doesn't... 🤷‍♂️

So i'd like to know if any of you humans know if this really is the expected behavior ?

I've googled this issue a lot and havent found any slutions and likewize the AI's didn't have any solutions either.


r/WindowsServer 11d ago

Technical Help Needed DHCP Post-install configuration wizard problem

3 Upvotes

So I installed DHCP but the post-install configuration only features the Description and Summary in the popup. The tutorial I followed shows that there's supposed to be an Authorization part but mine doesn't show that. What should I do about this? Thank you


r/WindowsServer 11d ago

General Question Server 2016 Essentials - Clone system disk and restore to different hardware?

2 Upvotes

I have a home server running 2016 Essentials. (I know that is probably below the level of the majority of members here, but hoping for some guidance.)

It is running on an old HP Proliant N54 (AMD). Mostly used as a file server and bare metal backup and restore solution. I do have a photo library application that runs on PostgreSQL.

The old box is not expandable and is lightly powered by today's standards.

I purchased a refurbished Dell T340 (Intel Xeon) and want to migrate the server install to it. I have tried to find driver INF files, but all I can find on Dell site is EXE files.

The system disk is a 1 TB SATA SSD. I have a second unformatted disk as a clone target. (Dell T340 does not support NVME.)

I know Acronis True Image has a Universal Restore feature, but it will not install on a server.

I would like to backup or clone the SSD (with all partitions), then restore it to the new hardware while having it deal with the HAL issues going from AMD to Intel.

It looks like I can purchase the Acronis Cyberprotect Backup for this, although it seems like using a hammer to swat a fly.

TL;DR: Can anyone recommend a method/software to migrate WSE 2016 installation from AMD machine to Intel machine?


r/WindowsServer 12d ago

General Server Discussion Made A Free Discord server That Pings & Emails You The Moment A Critical CVE Drops For Dozens Of Vendors (Select & Choose), Wiindows Server CVEs Are One Of Them. Mitigation & Resource Documentation/Discussions As-Well

12 Upvotes

I created a simple Discord server that automatically updates vendor-specific channels whenever a new CVE is published from that specific vendor.

It tags users based on the roles they choose, so you can follow the vendors you care about and decide whether you only want to be tagged for critical alerts. You can also choose to receive an email as well when that CVE drops.

I’ve also added discussion channels where we can share patching tips, troubleshooting advice, and general networking/security/sysadmin knowledge, plus resource channels for each vendor with quick links to relevant documentation (Official Vendor Advisory Feed etc).

Just wanted to help myself and other Network/Sys/Devs make their already complicated lives easier.

It’s completely free to join.

https://discord.gg/duxkwSSAAH


r/WindowsServer 12d ago

General Server Discussion VM got removed from the WSUS Server

2 Upvotes

We normally patch all our servers through WSUS, and this VM was updated through WSUS last month without any issues. But this month I noticed it had disappeared from the WSUS console.

When I checked the registry, all the WSUS related settings were missing. We haven't made any changes to this server, so I'm trying to figure out what could have caused this.

Because of that, the VM is now getting Windows updates directly from the internet, which isn't acceptable since it's a production server.

Has anyone seen this happen before? What are the possible reasons a server would suddenly lose its WSUS configuration and stop reporting to WSUS?


r/WindowsServer 13d ago

SOLVED / ANSWERED Print Server Issues

5 Upvotes

I am setting up a Windows 2025 server as a print server. As long as my clients are connecting via a wire network connection, everything works just fine. My users that connect over wireless are having some issues. I think I have all the necessary ports open on the firewall but still no luck. Also, for those that are on the wireless, because of how our network is set up, they have to connect using our corporate VPN.

These are the ports that I have open.

135 tcp/udp

161 tcp/udp

515 tcp

631 tcp

3389 tcp/udp

Admittedly Windows server is not my primary platform, I'm primarily a linux admin, but this print server has to be Windows. Any suggestions of what directions to direct my search efforts would be greatly appreciated.


r/WindowsServer 13d ago

Technical Help Needed Windows Server 2025 activation fails

7 Upvotes

A installed Microsoft Windows Server 2025 Standard Evaluation should actually be upgradeable to an activated Microsoft Windows Server 2025 Standard with:

DISM /online /Set-Edition:ServerStandard /ProductKey:"product-Key" /AcceptEula

which has worked without any problems with that image so far.

Now, however, the command is failing, and the following command brings that result, instead of offering

ServerStandard

or

Datacenter Edition

Now I get this result:

PS D:\> DISM.exe /Online /Get-TargetEditions

Tool zur Imageverwaltung für die Bereitstellung

Version: 10.0.26100.5074

Abbildversion: 10.0.26100.32995

Editionen, auf die aktualisiert werden kann:

Zieledition : ServerTurbineCor

Zieledition : ServerDatacenterCor

Der Vorgang wurde erfolgreich beendet.

I checked now every installed Server 2025 I found and got the same result.

I can update to this ServerTurbineCor with the right key, but I can't buy that licence

The ServerStandard already aktivatet run fine


r/WindowsServer 13d ago

Technical Help Needed Win 2025 try to connect to Microsoft while login

0 Upvotes

Hello, it appears that Windows 2025 attempts to connect to login.microsoftonline.com during the Windows login process, but only with domain users.

As this is a DMZ server with restricted internet access, the login process takes a very long time (approx. 2 minutes), which causes our 2FA solution to time out. Local users should not be able to connect to Microsoft. Is there a way to prevent these connection attempts and thus speed up the login process? The slow login only occurs the day after configuring the system on a closed network. Something is happening here overnight – perhaps it’s related to caching.

Thank you


r/WindowsServer 14d ago

Technical Help Needed Personal Drive Not Remounting After Sleep

0 Upvotes

We are using Windows Server 2012 that has a script to connect and set the users personal drive to a folder on the file server. After updating one of the users computers to Windows 11, their personal drive connects fine when they login, but when the computer wakes from sleep, it is disconnected.

The user has other mapped drives that point to shared folders on the same server the personal drive is on, and those remain connected/reconnect just fine after sleep.

I've disabled the network adapter power management and updated the local group policy to wait for the network at computer startup and logon. The issue persists.

This issues seems to be isolated to this one user/computer. Any ideas on what else could be causing this?