You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory-domain-services/active-directory-ds-admin-guide-configure-secure-ldap.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
15
ms.devlang: na
16
16
ms.topic: conceptual
17
-
ms.date: 09/25/2018
17
+
ms.date: 11/02/2018
18
18
ms.author: ergreenl
19
19
20
20
---
@@ -41,7 +41,7 @@ Acquire a valid certificate per the following guidelines, before you enable secu
41
41
42
42
1.**Trusted issuer** - The certificate must be issued by an authority trusted by computers connecting to the managed domain using secure LDAP. This authority may be a public certification authority (CA) or an Enterprise CA trusted by these computers.
43
43
2.**Lifetime** - The certificate must be valid for at least the next 3-6 months. Secure LDAP access to your managed domain is disrupted when the certificate expires.
44
-
3.**Subject name** - The subject name on the certificate must be your managed domain name. For instance, if your domain is named 'contoso100.com', the certificate's subject name must be 'contoso100.com'.
44
+
3.**Subject name** - The subject name on the certificate must be a wildcard for your managed domain. For instance, if your domain is named 'contoso100.com', the certificate's subject name must be 'contoso100.com'. Set the DNS name (subject alternate name) to this wildcard name.
45
45
4.**Key usage** - The certificate must be configured for the following uses - Digital signatures and key encipherment.
46
46
5.**Certificate purpose** - The certificate must be valid for SSL server authentication.
Copy file name to clipboardExpand all lines: articles/active-directory-domain-services/active-directory-ds-troubleshoot-alerts.md
+53-28Lines changed: 53 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
15
ms.devlang: na
16
16
ms.topic: article
17
-
ms.date: 10/25/2018
17
+
ms.date: 11/02/2018
18
18
ms.author: ergreenl
19
19
20
20
---
@@ -35,13 +35,15 @@ Pick the troubleshooting steps that correspond to the ID or message in the alert
35
35
| AADDS105 |*The service principal with the application ID “d87dcbc6-a371-462e-88e3-28ad15ec4e64” was deleted and then recreated. The recreation leaves behind inconsistent permissions on Azure AD Domain Services resources needed to service your managed domain. Synchronization of passwords on your managed domain could be affected.*|[The password synchronization application is out of date](active-directory-ds-troubleshoot-service-principals.md#alert-aadds105-password-synchronization-application-is-out-of-date)|
36
36
| AADDS106 |*Your Azure subscription associated with your managed domain has been deleted. Azure AD Domain Services requires an active subscription to continue functioning properly.*|[Azure subscription is not found](#aadds106-your-azure-subscription-is-not-found)|
37
37
| AADDS107 |*Your Azure subscription associated with your managed domain is not active. Azure AD Domain Services requires an active subscription to continue functioning properly.*|[Azure subscription is disabled](#aadds107-your-azure-subscription-is-disabled)|
38
-
| AADDS108 |*A resource that is used for your managed domain has been deleted. This resource is needed for Azure AD Domain Services to function properly.*|[A resource has been deleted](#aadds108-resources-for-your-managed-domain-cannot-be-found)|
39
-
| AADDS109 |*The subnet selected for deployment of Azure AD Domain Services is full, and does not have space for the additional domain controller that needs to be created.*|[Subnet is full](#aadds109-the-subnet-associated-with-your-managed-domain-is-full)|
40
-
| AADDS110 |*We have identified that the subnet of the virtual network in this domain may not have enough IP addresses. Azure AD Domain Services needs at-least two available IP addresses within the subnet it is enabled in. We recommend having at-least 3-5 spare IP addresses within the subnet. This may have occurred if other virtual machines are deployed within the subnet, thus exhausting the number of available IP addresses or if there is a restriction on the number of available IP addresses in the subnet.*|[Not enough IP addresses](#aadds110-not-enough-ip-address-in-the-managed-domain)|
41
-
| AADDS111 |*One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.*|[Resources are locked](#aadds111-resources-are-locked)|
42
-
| AADDS112 |*One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).*|[Resources are unusable](#aadds112-resources-are-unusable)|
38
+
| AADDS108 |*The subscription used by Azure AD Domain Services has been moved to another directory. Azure AD Domain Services needs to have an active subscription in the same directory to function properly.*|[Subscription moved directories](#aadds108-subscription-moved-directories)|
39
+
| AADDS109 |*A resource that is used for your managed domain has been deleted. This resource is needed for Azure AD Domain Services to function properly.*|[A resource has been deleted](#aadds109-resources-for-your-managed-domain-cannot-be-found)|
40
+
| AADDS110 |*The subnet selected for deployment of Azure AD Domain Services is full, and does not have space for the additional domain controller that needs to be created.*|[Subnet is full](#aadds110-the-subnet-associated-with-your-managed-domain-is-full)|
41
+
| AADDS111 |*A service principal that Azure AD Domain Services uses to service your domain is not authorized to manage resources on the Azure subscription. The service principal needs to gain permissions to service your managed domain. * |[Service principal unauthorized](#aadds111-service-principal-unauthorized)|
42
+
| AADDS112 |*We have identified that the subnet of the virtual network in this domain may not have enough IP addresses. Azure AD Domain Services needs at-least two available IP addresses within the subnet it is enabled in. We recommend having at-least 3-5 spare IP addresses within the subnet. This may have occurred if other virtual machines are deployed within the subnet, thus exhausting the number of available IP addresses or if there is a restriction on the number of available IP addresses in the subnet.*|[Not enough IP addresses](#aadds112-not-enough-ip-address-in-the-managed-domain)|
43
43
| AADDS113 |*The resources used by Azure AD Domain Services were detected in an unexpected state and cannot be recovered.*|[Resources are unrecoverable](#aadds113-resources-are-unrecoverable)|
44
-
| AADDS114 |*Azure AD Domain Services domain controllers are not able to access port 443. It is needed to service, manage, and update your managed domain. * |[Port 442 blocked](#aadds114-port-443-blocked)|
44
+
| AADDS114 |*The subnet selected for deployment of Azure AD Domain Services is invalid, and cannot be used. * |[Subnet invalid](#aadds114-subnet-invalid)|
45
+
| AADDS115 |*One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.*|[Resources are locked](#aadds115-resources-are-locked)|
46
+
| AADDS116 |*One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).*|[Resources are unusable](#aadds116-resources-are-unusable)|
45
47
| AADDS500 |*The managed domain was last synchronized with Azure AD on [date]. Users may be unable to sign-in on the managed domain or group memberships may not be in sync with Azure AD.*|[Synchronization hasn't happened in a while](#aadds500-synchronization-has-not-completed-in-a-while)|
46
48
| AADDS501 |*The managed domain was last backed up on [date].*|[A backup hasn't been taken in a while](#aadds501-a-backup-has-not-been-taken-in-a-while)|
47
49
| AADDS502 |*The secure LDAP certificate for the managed domain will expire on [date].*|[Expiring secure LDAP certificate](active-directory-ds-troubleshoot-ldaps.md#aadds502-secure-ldap-certificate-expiring)|
@@ -134,7 +136,17 @@ Azure AD Domain Services requires a subscription to function and cannot be moved
134
136
1.[Renew your Azure subscription](https://docs.microsoft.com/azure/billing/billing-subscription-become-disable).
135
137
2. Once the subscription is renewed, Azure AD Domain Services will receive a notification from Azure to re-enable your managed domain.
136
138
137
-
## AADDS108: Resources for your managed domain cannot be found
139
+
## AADDS108: Subscription moved directories
140
+
141
+
**Alert message:**
142
+
143
+
*The subscription used by Azure AD Domain Services has been moved to another directory. Azure AD Domain Services needs to have an active subscription in the same directory to function properly.*
144
+
145
+
**Resolution:**
146
+
147
+
You can either move the subscription associated with Azure AD Domain Services back to the previous directory, or you need to [delete your managed domain](active-directory-ds-disable-aadds.md) from the existing directory and recreate it in the chosen directory (either with a new subscription or change the directory your Azure AD Domain Services instance is in).
148
+
149
+
## AADDS109: Resources for your managed domain cannot be found
138
150
139
151
**Alert message:**
140
152
@@ -145,15 +157,15 @@ Azure AD Domain Services requires a subscription to function and cannot be moved
145
157
Azure AD Domain Services creates specific resources while deploying in order to function properly, including public IP addresses, NICs, and a load balancer. If any of the named are deleted, this causes your managed domain to be in an unsupported state and prevents your domain from being managed. This alert is found when someone who is able to edit the Azure AD Domain Services resources deletes a needed resource. The following steps outline how to restore your managed domain.
146
158
147
159
1. Navigate to the Azure AD Domain Services health page
148
-
1. Travel to the [Azure AD Domain Services page]() in the Azure portal.
160
+
1. Travel to the [Azure AD Domain Services page](https://portal.azure.com/#blade/HubsExtension/Resources/resourceType/Microsoft.AAD%2FdomainServices) in the Azure portal.
149
161
2. In the left-hand navigation, click **Health**
150
162
2. Check to see if the alert is less than 4 hours old
151
-
1. On the health page, click the alert with the ID **AADDS108**
163
+
1. On the health page, click the alert with the ID **AADDS109**
152
164
2. The alert will have a timestamp for when it was first found. If that timestamp is less than 4 hours ago, there is a chance that Azure AD Domain Services can recreate the deleted resource.
153
165
3. If the alert is more than 4 hours old, the managed domain is in an unrecoverable state. You must delete and recreate Azure AD Domain Services.
154
166
155
167
156
-
## AADDS109: The subnet associated with your managed domain is full
168
+
## AADDS110: The subnet associated with your managed domain is full
157
169
158
170
**Alert message:**
159
171
@@ -163,8 +175,21 @@ Azure AD Domain Services creates specific resources while deploying in order to
163
175
164
176
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md)
165
177
178
+
## AADDDS111: Service principal unauthorized
179
+
180
+
**Alert message:**
166
181
167
-
## AADDS110: Not enough IP address in the managed domain
182
+
*A service principal that Azure AD Domain Services uses to service your domain is not authorized to manage resources on the Azure subscription. The service principal needs to gain permissions to service your managed domain.*
183
+
184
+
**Resolution:**
185
+
186
+
Our service principals need access to be able to manage and create resources on your managed domain. Someone has denied the service principal access and now it is unable to manage resources. Follow the steps to grant access to your service principal.
187
+
188
+
1. Read about [RBAC control and how to grant access to applications on the Azure portal](https://docs.microsoft.com/azure/role-based-access-control/role-assignments-portal)
189
+
2. Review the access that the service principal with the ID ```abba844e-bc0e-44b0-947a-dc74e5d09022``` and grant the access that was denied at an earlier date.
190
+
191
+
192
+
## AADDS112: Not enough IP address in the managed domain
168
193
169
194
**Alert message:**
170
195
@@ -185,48 +210,48 @@ This error is unrecoverable. To resolve, you must [delete your existing managed
185
210
4. To domain-join your virtual machines to your new domain, follow [this guide](https://docs.microsoft.com/azure/active-directory-domain-services/active-directory-ds-admin-guide-join-windows-vm-portal).
186
211
5. Check your domain's health in two hours to ensure that you have completed the steps correctly.
187
212
188
-
## AADDS111: Resources are locked
213
+
## AADDS113: Resources are unrecoverable
189
214
190
215
**Alert message:**
191
216
192
-
*One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.*
217
+
*The resources used by Azure AD Domain Services were detected in an unexpected state and cannot be recovered.*
193
218
194
219
**Resolution:**
195
220
196
-
1. Review Resource Manager operation logs on the network resources (this should give info on which lock is preventing modification).
197
-
2. Remove the locks on the resources so that the Azure AD Domain Services service principal can operate on them.
198
-
221
+
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md).
199
222
200
-
## AADDS112: Resources are unusable
223
+
## AADDS114: Subnet invalid
201
224
202
225
**Alert message:**
203
226
204
-
*One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).*
227
+
*The subnet selected for deployment of Azure AD Domain Services is invalid, and cannot be used.*
205
228
206
229
**Resolution:**
207
230
208
-
1. Review Resource Manager operation logs on the network resources for your managed domain
209
-
2. Weaken the policy restrictions on the resources so that the AAD-DS service principal can operate on them.
231
+
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md).
210
232
211
-
## AADDS113: Resources are unrecoverable
233
+
## AADDS115: Resources are locked
212
234
213
235
**Alert message:**
214
236
215
-
*The resources used by Azure AD Domain Services were detected in an unexpected state and cannot be recovered.*
237
+
*One or more of the network resources used by the managed domain cannot be operated on as the target scope has been locked.*
216
238
217
239
**Resolution:**
218
240
219
-
This error is unrecoverable. To resolve, you must [delete your existing managed domain](active-directory-ds-disable-aadds.md) and [recreate your managed domain](active-directory-ds-getting-started.md)
241
+
1. Review Resource Manager operation logs on the network resources (this should give info on which lock is preventing modification).
242
+
2. Remove the locks on the resources so that the Azure AD Domain Services service principal can operate on them.
220
243
221
-
## AADDS114: Port 443 Blocked
244
+
## AADDS116: Resources are unusable
222
245
223
246
**Alert message:**
224
247
225
-
*Azure AD Domain Services domain controllers are not able to access port 443. It is needed to service, manage, and update your managed domain.*
248
+
*One or more of the network resources used by the managed domain cannot be operated on due to policy restriction(s).*
226
249
227
250
**Resolution:**
228
251
229
-
Allow inbound access through port 443 on your network security group for Azure AD Domain Services.
252
+
1. Review Resource Manager operation logs on the network resources for your managed domain.
253
+
2. Weaken the policy restrictions on the resources so that the AAD-DS service principal can operate on them.
254
+
230
255
231
256
232
257
## AADDS500: Synchronization has not completed in a while
@@ -251,7 +276,7 @@ Here are some common reasons why synchronization stops on managed domains:
251
276
252
277
**Resolution:**
253
278
254
-
[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. Sometimes, problems with your configuration can block Microsoft's ability to synchronize your managed domain. If you are able to resolve any alerts, wait two hours and check back to see if the synchronization has completed.
279
+
[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. Sometimes, problems with your configuration can block Microsoft's ability to back up your managed domain. If you are able to resolve any alerts, wait two hours and check back to see if the backup has completed.
255
280
256
281
257
282
## AADDS503: Suspension due to disabled subscription
0 commit comments