Automating DOMAIN USERS (Active Directory #02)

Поділитися
Вставка
  • Опубліковано 1 лют 2025

КОМЕНТАРІ • 63

  • @Guldbullen
    @Guldbullen 2 роки тому +21

    I think it was funny that the website you did troubleshoot the trust relationship problem, the actually solution was there and you skipped it and said that is some weird stuff =)
    The problem is that the computer password has changed (it's on a timer) in AD, when you did your snapshot restore back in time the computer password don't match the AD password. Im talking about the computer AD object now, not the user.
    To fix it, login with local admin account, open PS as admin:
    Reset-ComputerMachinePassword -Server "ADServerName" -Credential Domain\DomainUserWithRights
    To avoid this you can set in registry not to change the password automaticly:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
    change DisablePasswordChange from 0 to 1
    And big thanks to your videos, they are great =)

    • @BrianFurios
      @BrianFurios 2 роки тому +1

      If the domain user already logged in, you can disconnect the ethernet just to use the cached password, then you can replug it and rejoin the domain.
      If you want to rejoin the domain without rebooting the machine twice, you can just remove the tld (.local, .com etc), in your case ".com"
      After that reboot your PC is resynced with the domain

  • @preveenramcharan
    @preveenramcharan 2 роки тому +21

    Dude, whatever you do, don't stop doing these videos. I can't remember the last time I watched a 50min video without falling asleep. You're awesome buddy. Keep up the great work!!!

    • @v01d_r34l1ty
      @v01d_r34l1ty 2 роки тому +7

      I remember the last time I watched a 50 min video without falling asleep. It was all of John's Malware Analysis videos. Wish he'd do more.

    • @MD4564
      @MD4564 2 роки тому

      1000% love them.

  • @ratchetbear5916
    @ratchetbear5916 2 роки тому +2

    Hey John, i really appreciate you taking the time to cover AD in this much depth.
    I'm preparing to undertake my OSCP, i think (without 100% knowing) this will go a long ways with helping me reach that goal!
    Best of luck to you, can looking forward to seeing more! :)

  • @Bjon10
    @Bjon10 2 роки тому +1

    Thank you for being the person that you are, loving this AD series!!

  • @bubbl_media
    @bubbl_media 2 роки тому

    These videos are so helpful. Thank you very much for your perfect tutorials without cutting out the errors and troubleshooting.

  • @AdamEickhoff
    @AdamEickhoff 2 роки тому +1

    I was so waiting for you to use PowerShell splatting. It's a really clean way to pass arguments (with values) to cmdlets.

  • @flirtyemy042
    @flirtyemy042 2 роки тому +3

    I love the whole learning by teaching concept.

  • @SoulJah876
    @SoulJah876 2 роки тому +2

    This was dope. Nice dive into PS and AD for me. Thanks.

  • @p0z0x86
    @p0z0x86 2 роки тому +5

    When you were getting the message trying to log on, I was shouting at my screen about the revert to a clean snapshot 😂

    • @_JohnHammond
      @_JohnHammond  2 роки тому +2

      We spend some time fixing it in the next video, because it makes it a pain.

    • @ra1d3r34
      @ra1d3r34 2 роки тому

      @@_JohnHammond Oh yes, its such a hassle. I´m admin for a software company and i have to deploy or rollback VMs on a daily basis.
      But it has become lazy practice to just reinstall fully automated and just link in a data drive afterwards.
      Other approach is to roll back all related lab machines at once.
      I´m learning more here about Powershell than in any tutorial i´ve watched before. (okay .. i like Python better, got it installed on every machine in our company)

  • @anamnesis726
    @anamnesis726 11 місяців тому

    Super nice thx ! I like to see your methodology and the troubleshooting ! I learn so much from your videos and this is a cool project! ;)

  • @notta3d
    @notta3d 2 роки тому

    Awesome stuff! I love the thought process of working through it. Please keep going.

  • @skyhacker5481
    @skyhacker5481 2 роки тому +1

    Great man your really doing great from last 10 year's 🙌🙌🙌

  • @enpassant7358
    @enpassant7358 2 роки тому +1

    I am so glad to see that Windows doesn't behave as expected for you at times. I thought it was just me. lol

  • @nixielee
    @nixielee 2 роки тому +1

    The thickness of that Win11 taskbar is insane

  • @vampyweekies
    @vampyweekies 2 роки тому +1

    Haha, this is awesome! You think it took you a long time? I tried to follow along without necessarily just copying your code, I messed something up with the "catch" process for adding users to groups, and it took me like two hours to figure out why it was breaking...

  • @himashhimash6017
    @himashhimash6017 2 роки тому +1

    AD from hammond's university .... thank you for the content 🙂

  • @ForSquirel
    @ForSquirel 2 роки тому +1

    I saw this exact error @ ~minute 39 last week. As soon as I heard it I knew exactly what was up. Its definitely 'scary' the first time you see it.

  • @BlubImAFish
    @BlubImAFish 2 роки тому +2

    10:21 Doing some googleing on the fly together --Meanwhile continues to use bing

  • @NolanNonprivate
    @NolanNonprivate Рік тому

    This series is awsome.

  • @jordy6292
    @jordy6292 2 роки тому

    Awesome video John, thanks!

  • @dazza3d154
    @dazza3d154 2 роки тому

    Hi John,
    great stuff, It's been a while but I remember back on server 2008, loading users etc from a CSV file, But I like coding.... Cheers Darren

  • @nicdm81
    @nicdm81 2 роки тому

    Awesome video as usual!

  • @shivamsiyani3991
    @shivamsiyani3991 2 роки тому +3

    Go on we need you to teach us red and blue teaming with this plz continue it

  • @nebuen
    @nebuen 2 роки тому

    great video. quick question where did you buy that shirt ?

  • @j-makkk5208
    @j-makkk5208 2 роки тому

    Love these videos so much to learn

  • @ThaLiquidEdit
    @ThaLiquidEdit 2 роки тому +1

    I like long quality videos!

  • @nemowhere
    @nemowhere 2 роки тому

    you are so smart!

  • @codylwaller
    @codylwaller 2 роки тому

    Can you also do a server hardening series?

  • @sambitmishra9428
    @sambitmishra9428 2 роки тому

    🤩🤩

  • @guilherme5094
    @guilherme5094 2 роки тому

    👍

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Brother confusion tool confusion.

  • @rameezbinayaz8146
    @rameezbinayaz8146 2 роки тому +1

    Is it *(AD #03)* OR *(AD #02)*

  • @jonstart4185
    @jonstart4185 2 роки тому

    How do I remove an existing active directory? My pc won't allow me to follow your steps coz of the existing one

    • @shadaxgaming
      @shadaxgaming 2 роки тому +1

      If you have an AD setup, it shouldn't really matter. Granted I haven't watched this video yet, but to "remove" AD you'd have to uninstall ADDS Domain Controller to destroy it.

    • @jonstart4185
      @jonstart4185 2 роки тому

      @@shadaxgaming thanks, appreciate 🙏

    • @shadaxgaming
      @shadaxgaming 2 роки тому

      @@jonstart4185 Any time Jon. Good luck.

    • @superfish4603
      @superfish4603 2 роки тому

      did you install AD on your actual PC? O.o

  • @evil-cougars9147
    @evil-cougars9147 2 роки тому

    im confused y is this unlisted and im lost this hould be #3

  • @sheesh236
    @sheesh236 2 роки тому

    Me too

  • @Naha-ir9mi
    @Naha-ir9mi 2 роки тому

    I thought it was already uploaded bruh

  • @jarjarchared
    @jarjarchared 2 роки тому

    Get the hell out of my head, I was literally doing this exact same thing Friday.

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Administrator password mini status?

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Licence attending for you window open

  • @superfish4603
    @superfish4603 2 роки тому

    $Mandatory

  • @maelteprah123
    @maelteprah123 2 роки тому

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Domnam comnnamam

  • @AsadAli-ye8ns
    @AsadAli-ye8ns 2 роки тому

    idk why this guy doing everything with CLI, while you can do with GUI easily, in just 5 minutes....

    • @huleinpylo3906
      @huleinpylo3906 2 роки тому +2

      If you have a DC without any gui it is practical to know the cli.
      Also automatisation

    • @mikeg8543
      @mikeg8543 2 роки тому +2

      I wrote a script to automate user creation and AD grouping for specific OU's took me about an hour but it saved me from entering 80 users manually for my project.

    • @jonasrivers3675
      @jonasrivers3675 2 роки тому +1

      A shell is a shell is a shell.

  • @pcfverbeek
    @pcfverbeek 2 роки тому

    There is Test-Computersecurechannel to check if computer is still trusted on domain and if trust is broken you restore it with Test-Computersecurechannel -repair -credential username/pw