- Common problems and their solutions
- How to use built-in troubleshooting tools
- Best practices for problem-solving
- How to prevent issues before they happen
- A working Windows Server domain (from 01_Setup_Lab_Environment.md)
- Basic understanding of Active Directory concepts
-
Check Account Status
- Open Active Directory Users and Computers
- Right-click user → Properties
- Verify account is enabled
- Check if password is expired
-
Verify Group Membership
- Check if user is in correct groups
- Look for deny permissions
- Verify OU placement
-
Check Password Policy
- Run
gpresult /ron client - Verify password meets requirements
- Check if account is locked
- Run
- Reset password if needed
- Unlock account if locked
- Add to required groups
- Move to correct OU
-
Check Network
- Verify IP settings
- Test DNS resolution
- Check firewall settings
-
Verify DNS
- Run
nslookup lab.local - Check DNS server settings
- Verify DNS records
- Run
-
Check Computer Account
- Look for existing account
- Verify computer name
- Check OU placement
- Set correct DNS server
- Create computer account
- Join domain with admin credentials
- Restart computer
-
Check GPO Status
- Verify GPO is enabled
- Check if linked to correct OU
- Look for inheritance issues
-
Verify Client Settings
- Run
gpupdate /force - Check event logs
- Verify network connectivity
- Run
-
Check GPO Order
- Look for conflicting GPOs
- Verify link order
- Check for enforced GPOs
- Enable GPO if disabled
- Link to correct OU
- Fix inheritance issues
- Update client settings
# Check DNS resolution
nslookup lab.local
# Flush DNS cache
ipconfig /flushdns
# Register DNS
ipconfig /registerdns# Force GPO update
gpupdate /force
# Check GPO results
gpresult /r
# Check GPO status
gpresult /h report.html# Check AD replication
repadmin /showrepl
# Check AD health
dcdiag /v
# Check FSMO roles
netdom query fsmo- Press
Windows + R - Type
eventvwr.msc - Check:
- System logs
- Application logs
- Directory Service logs
-
Users and Computers
- Press
Windows + R - Type
dsa.msc - Check user/computer properties
- Press
-
Sites and Services
- Press
Windows + R - Type
dssite.msc - Check replication
- Press
-
Domains and Trusts
- Press
Windows + R - Type
domain.msc - Check trust relationships
- Press
- Keep records of changes
- Document network settings
- Maintain password policies
- Track GPO modifications
- Test changes in lab first
- Use test OUs for new policies
- Verify backups before changes
- Document test results
- Check event logs regularly
- Monitor disk space
- Watch for failed logins
- Track GPO application
-
Check FSMO roles
-
Verify replication
-
Check DNS settings
-
Restart services:
net stop ntds net start ntds
- Check DNS server settings
- Verify forwarders
- Check zone transfers
- Update DNS records
- Stop AD services
- Run integrity check
- Repair if needed
- Restart services
- Multiple DCs down
- Complete authentication failure
- Data corruption
- Security breaches
- Frequent replication errors
- Growing event log errors
- Slow logon times
- Failed backups
- Review previous guides: