Skip to content

Commit f0c2758

Browse files
authored
Merge pull request #57173 from MicrosoftDocs/master
11/5 PM Publish
2 parents 00dd50f + 34b200e commit f0c2758

File tree

171 files changed

+1200
-769
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

171 files changed

+1200
-769
lines changed

articles/active-directory-b2c/active-directory-b2c-custom-setup-adfs2016-idp.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ manager: mtillman
88
ms.service: active-directory
99
ms.workload: identity
1010
ms.topic: conceptual
11-
ms.date: 09/20/2018
11+
ms.date: 11/05/2018
1212
ms.author: davidmu
1313
ms.component: B2C
1414
---
@@ -60,6 +60,7 @@ You can define an ADFS account as a claims provider by adding it to the **Claims
6060
<Metadata>
6161
<Item Key="WantsEncryptedAssertions">false</Item>
6262
<Item Key="PartnerEntity">https://your-ADFS-domain/federationmetadata/2007-06/federationmetadata.xml</Item>
63+
<Item Key=" XmlSignatureAlgorithm">Sha256</Item>
6364
</Metadata>
6465
<CryptographicKeys>
6566
<Key Id="SamlAssertionSigning" StorageReferenceId="B2C_1A_ADFSSamlCert"/>

articles/active-directory-domain-services/TOC.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33
# Overview
44
## [What is Azure AD Domain Services?](active-directory-ds-overview.md)
5+
## [FAQs](active-directory-ds-faqs.md)
56
## Is it right for you?
67
### [Compare with Windows Server AD](active-directory-ds-comparison.md)
78
### [Compare with Azure AD join](active-directory-ds-compare-with-azure-ad-join.md)
@@ -55,7 +56,6 @@
5556
## [Troubleshoot secure LDAP](active-directory-ds-ldaps-troubleshoot.md)
5657

5758
# Troubleshoot
58-
## [FAQs](active-directory-ds-faqs.md)
5959
## [Troubleshooting guide](active-directory-ds-troubleshooting.md)
6060
## [Troubleshoot alerts](active-directory-ds-troubleshoot-alerts.md)
6161
### [Fix a broken NSG configuration](active-directory-ds-troubleshoot-nsg.md)

articles/active-directory-domain-services/active-directory-ds-admin-guide-configure-secure-ldap.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.workload: identity
1414
ms.tgt_pltfrm: na
1515
ms.devlang: na
1616
ms.topic: conceptual
17-
ms.date: 09/25/2018
17+
ms.date: 11/02/2018
1818
ms.author: ergreenl
1919

2020
---
@@ -41,7 +41,7 @@ Acquire a valid certificate per the following guidelines, before you enable secu
4141

4242
1. **Trusted issuer** - The certificate must be issued by an authority trusted by computers connecting to the managed domain using secure LDAP. This authority may be a public certification authority (CA) or an Enterprise CA trusted by these computers.
4343
2. **Lifetime** - The certificate must be valid for at least the next 3-6 months. Secure LDAP access to your managed domain is disrupted when the certificate expires.
44-
3. **Subject name** - The subject name on the certificate must be your managed domain name. For instance, if your domain is named 'contoso100.com', the certificate's subject name must be 'contoso100.com'.
44+
3. **Subject name** - The subject name on the certificate must be a wildcard for your managed domain. For instance, if your domain is named 'contoso100.com', the certificate's subject name must be 'contoso100.com'. Set the DNS name (subject alternate name) to this wildcard name.
4545
4. **Key usage** - The certificate must be configured for the following uses - Digital signatures and key encipherment.
4646
5. **Certificate purpose** - The certificate must be valid for SSL server authentication.
4747

articles/active-directory-domain-services/active-directory-ds-troubleshoot-alerts.md

Lines changed: 53 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.workload: identity
1414
ms.tgt_pltfrm: na
1515
ms.devlang: na
1616
ms.topic: article
17-
ms.date: 10/25/2018
17+
ms.date: 11/02/2018
1818
ms.author: ergreenl
1919

2020
---
@@ -35,13 +35,15 @@ Pick the troubleshooting steps that correspond to the ID or message in the alert
3535
| AADDS105 | *The service principal with the application ID “d87dcbc6-a371-462e-88e3-28ad15ec4e64” was deleted and then recreated. The recreation leaves behind inconsistent permissions on Azure AD Domain Services resources needed to service your managed domain. Synchronization of passwords on your managed domain could be affected.* | [The password synchronization application is out of date](active-directory-ds-troubleshoot-service-principals.md#alert-aadds105-password-synchronization-application-is-out-of-date) |
3636
| AADDS106 | *Your Azure subscription associated with your managed domain has been deleted. Azure AD Domain Services requires an active subscription to continue functioning properly.* | [Azure subscription is not found](#aadds106-your-azure-subscription-is-not-found) |
3737
| AADDS107 | *Your Azure subscription associated with your managed domain is not active. Azure AD Domain Services requires an active subscription to continue functioning properly.* | [Azure subscription is disabled](#aadds107-your-azure-subscription-is-disabled) |
38-
| AADDS108 | *A resource that is used for your managed domain has been deleted. This resource is needed for Azure AD Domain Services to function properly.* | [A resource has been deleted](#aadds108-resources-for-your-managed-domain-cannot-be-found) |
39-
| AADDS109 | *The subnet selected for deployment of Azure AD Domain Services is full, and does not have space for the additional domain controller that needs to be created.* | [Subnet is full](#aadds109-the-subnet-associated-with-your-managed-domain-is-full) |
40-
| AADDS110 | *We have identified that the subnet of the virtual network in this domain may not have enough IP addresses. Azure AD Domain Services needs at-least two available IP addresses within the subnet it is enabled in. We recommend having at-least 3-5 spare IP addresses within the subnet. This may have occurred if other virtual machines are deployed within the subnet, thus exhausting the number of available IP addresses or if there is a restriction on the number of available IP addresses in the subnet.* | [Not enough IP addresses](#aadds110-not-enough-ip-address-in-the-managed-domain) |
41-
| AADDS111 | *One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.* | [Resources are locked](#aadds111-resources-are-locked) |
42-
| AADDS112 | *One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).* | [Resources are unusable](#aadds112-resources-are-unusable) |
38+
| AADDS108 | *The subscription used by Azure AD Domain Services has been moved to another directory. Azure AD Domain Services needs to have an active subscription in the same directory to function properly.* | [Subscription moved directories](#aadds108-subscription-moved-directories) |
39+
| AADDS109 | *A resource that is used for your managed domain has been deleted. This resource is needed for Azure AD Domain Services to function properly.* | [A resource has been deleted](#aadds109-resources-for-your-managed-domain-cannot-be-found) |
40+
| AADDS110 | *The subnet selected for deployment of Azure AD Domain Services is full, and does not have space for the additional domain controller that needs to be created.* | [Subnet is full](#aadds110-the-subnet-associated-with-your-managed-domain-is-full) |
41+
| AADDS111 | *A service principal that Azure AD Domain Services uses to service your domain is not authorized to manage resources on the Azure subscription. The service principal needs to gain permissions to service your managed domain. * | [Service principal unauthorized](#aadds111-service-principal-unauthorized) |
42+
| AADDS112 | *We have identified that the subnet of the virtual network in this domain may not have enough IP addresses. Azure AD Domain Services needs at-least two available IP addresses within the subnet it is enabled in. We recommend having at-least 3-5 spare IP addresses within the subnet. This may have occurred if other virtual machines are deployed within the subnet, thus exhausting the number of available IP addresses or if there is a restriction on the number of available IP addresses in the subnet.* | [Not enough IP addresses](#aadds112-not-enough-ip-address-in-the-managed-domain) |
4343
| AADDS113 | *The resources used by Azure AD Domain Services were detected in an unexpected state and cannot be recovered.* | [Resources are unrecoverable](#aadds113-resources-are-unrecoverable) |
44-
| AADDS114 | *Azure AD Domain Services domain controllers are not able to access port 443. It is needed to service, manage, and update your managed domain. * | [Port 442 blocked](#aadds114-port-443-blocked) |
44+
| AADDS114 | *The subnet selected for deployment of Azure AD Domain Services is invalid, and cannot be used. * | [Subnet invalid](#aadds114-subnet-invalid) |
45+
| AADDS115 | *One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.* | [Resources are locked](#aadds115-resources-are-locked) |
46+
| AADDS116 | *One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).* | [Resources are unusable](#aadds116-resources-are-unusable) |
4547
| AADDS500 | *The managed domain was last synchronized with Azure AD on [date]. Users may be unable to sign-in on the managed domain or group memberships may not be in sync with Azure AD.* | [Synchronization hasn't happened in a while](#aadds500-synchronization-has-not-completed-in-a-while) |
4648
| AADDS501 | *The managed domain was last backed up on [date].* | [A backup hasn't been taken in a while](#aadds501-a-backup-has-not-been-taken-in-a-while) |
4749
| AADDS502 | *The secure LDAP certificate for the managed domain will expire on [date].* | [Expiring secure LDAP certificate](active-directory-ds-troubleshoot-ldaps.md#aadds502-secure-ldap-certificate-expiring) |
@@ -134,7 +136,17 @@ Azure AD Domain Services requires a subscription to function and cannot be moved
134136
1. [Renew your Azure subscription](https://docs.microsoft.com/azure/billing/billing-subscription-become-disable).
135137
2. Once the subscription is renewed, Azure AD Domain Services will receive a notification from Azure to re-enable your managed domain.
136138

137-
## AADDS108: Resources for your managed domain cannot be found
139+
## AADDS108: Subscription moved directories
140+
141+
**Alert message:**
142+
143+
*The subscription used by Azure AD Domain Services has been moved to another directory. Azure AD Domain Services needs to have an active subscription in the same directory to function properly.*
144+
145+
**Resolution:**
146+
147+
You can either move the subscription associated with Azure AD Domain Services back to the previous directory, or you need to [delete your managed domain](active-directory-ds-disable-aadds.md) from the existing directory and recreate it in the chosen directory (either with a new subscription or change the directory your Azure AD Domain Services instance is in).
148+
149+
## AADDS109: Resources for your managed domain cannot be found
138150

139151
**Alert message:**
140152

@@ -145,15 +157,15 @@ Azure AD Domain Services requires a subscription to function and cannot be moved
145157
Azure AD Domain Services creates specific resources while deploying in order to function properly, including public IP addresses, NICs, and a load balancer. If any of the named are deleted, this causes your managed domain to be in an unsupported state and prevents your domain from being managed. This alert is found when someone who is able to edit the Azure AD Domain Services resources deletes a needed resource. The following steps outline how to restore your managed domain.
146158

147159
1. Navigate to the Azure AD Domain Services health page
148-
1. Travel to the [Azure AD Domain Services page]() in the Azure portal.
160+
1. Travel to the [Azure AD Domain Services page](https://portal.azure.com/#blade/HubsExtension/Resources/resourceType/Microsoft.AAD%2FdomainServices) in the Azure portal.
149161
2. In the left-hand navigation, click **Health**
150162
2. Check to see if the alert is less than 4 hours old
151-
1. On the health page, click the alert with the ID **AADDS108**
163+
1. On the health page, click the alert with the ID **AADDS109**
152164
2. The alert will have a timestamp for when it was first found. If that timestamp is less than 4 hours ago, there is a chance that Azure AD Domain Services can recreate the deleted resource.
153165
3. If the alert is more than 4 hours old, the managed domain is in an unrecoverable state. You must delete and recreate Azure AD Domain Services.
154166

155167

156-
## AADDS109: The subnet associated with your managed domain is full
168+
## AADDS110: The subnet associated with your managed domain is full
157169

158170
**Alert message:**
159171

@@ -163,8 +175,21 @@ Azure AD Domain Services creates specific resources while deploying in order to
163175

164176
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md)
165177

178+
## AADDDS111: Service principal unauthorized
179+
180+
**Alert message:**
166181

167-
## AADDS110: Not enough IP address in the managed domain
182+
*A service principal that Azure AD Domain Services uses to service your domain is not authorized to manage resources on the Azure subscription. The service principal needs to gain permissions to service your managed domain.*
183+
184+
**Resolution:**
185+
186+
Our service principals need access to be able to manage and create resources on your managed domain. Someone has denied the service principal access and now it is unable to manage resources. Follow the steps to grant access to your service principal.
187+
188+
1. Read about [RBAC control and how to grant access to applications on the Azure portal](https://docs.microsoft.com/azure/role-based-access-control/role-assignments-portal)
189+
2. Review the access that the service principal with the ID ```abba844e-bc0e-44b0-947a-dc74e5d09022``` and grant the access that was denied at an earlier date.
190+
191+
192+
## AADDS112: Not enough IP address in the managed domain
168193

169194
**Alert message:**
170195

@@ -185,48 +210,48 @@ This error is unrecoverable. To resolve, you must [delete your existing managed
185210
4. To domain-join your virtual machines to your new domain, follow [this guide](https://docs.microsoft.com/azure/active-directory-domain-services/active-directory-ds-admin-guide-join-windows-vm-portal).
186211
5. Check your domain's health in two hours to ensure that you have completed the steps correctly.
187212

188-
## AADDS111: Resources are locked
213+
## AADDS113: Resources are unrecoverable
189214

190215
**Alert message:**
191216

192-
*One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.*
217+
*The resources used by Azure AD Domain Services were detected in an unexpected state and cannot be recovered.*
193218

194219
**Resolution:**
195220

196-
1. Review Resource Manager operation logs on the network resources (this should give info on which lock is preventing modification).
197-
2. Remove the locks on the resources so that the Azure AD Domain Services service principal can operate on them.
198-
221+
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md).
199222

200-
## AADDS112: Resources are unusable
223+
## AADDS114: Subnet invalid
201224

202225
**Alert message:**
203226

204-
*One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).*
227+
*The subnet selected for deployment of Azure AD Domain Services is invalid, and cannot be used.*
205228

206229
**Resolution:**
207230

208-
1. Review Resource Manager operation logs on the network resources for your managed domain
209-
2. Weaken the policy restrictions on the resources so that the AAD-DS service principal can operate on them.
231+
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md).
210232

211-
## AADDS113: Resources are unrecoverable
233+
## AADDS115: Resources are locked
212234

213235
**Alert message:**
214236

215-
*The resources used by Azure AD Domain Services were detected in an unexpected state and cannot be recovered.*
237+
*One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.*
216238

217239
**Resolution:**
218240

219-
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md)
241+
1. Review Resource Manager operation logs on the network resources (this should give info on which lock is preventing modification).
242+
2. Remove the locks on the resources so that the Azure AD Domain Services service principal can operate on them.
220243

221-
## AADDS114: Port 443 Blocked
244+
## AADDS116: Resources are unusable
222245

223246
**Alert message:**
224247

225-
*Azure AD Domain Services domain controllers are not able to access port 443. It is needed to service, manage, and update your managed domain.*
248+
*One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).*
226249

227250
**Resolution:**
228251

229-
Allow inbound access through port 443 on your network security group for Azure AD Domain Services.
252+
1. Review Resource Manager operation logs on the network resources for your managed domain.
253+
2. Weaken the policy restrictions on the resources so that the AAD-DS service principal can operate on them.
254+
230255

231256

232257
## AADDS500: Synchronization has not completed in a while
@@ -251,7 +276,7 @@ Here are some common reasons why synchronization stops on managed domains:
251276

252277
**Resolution:**
253278

254-
[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. Sometimes, problems with your configuration can block Microsoft's ability to synchronize your managed domain. If you are able to resolve any alerts, wait two hours and check back to see if the synchronization has completed.
279+
[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. Sometimes, problems with your configuration can block Microsoft's ability to back up your managed domain. If you are able to resolve any alerts, wait two hours and check back to see if the backup has completed.
255280

256281

257282
## AADDS503: Suspension due to disabled subscription

0 commit comments

Comments
 (0)