Kerberos

How to Configure Domain Trusts in Active Directory on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Domain Trusts in Active Directory on Windows Server 2016

How to Configure Windows Server 2016 Domain Trust Relationships Domain trust relationships in Windows Server 2016 enable users in one domain to access resources in another domain without requiring separate accounts in each domain. Trusts define the authentication relationships between domains and forests, determining how Kerberos and NTLM authentication flows across domain boundaries. Properly configuring […]

Read more
How to Configure NTLM Authentication on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure NTLM Authentication on Windows Server 2016

How to Set Up Windows Server 2016 NTLM Authentication NTLM (NT LAN Manager) is a challenge-response authentication protocol that predates Kerberos in the Windows ecosystem. While Kerberos is the preferred authentication protocol in Windows Server 2016 Active Directory environments, NTLM is still used in several scenarios: when clients connect using IP addresses instead of DNS […]

Read more
How to Configure Kerberos Authentication on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Kerberos Authentication on Windows Server 2016

How to Configure Windows Server 2016 Kerberos Authentication Kerberos is the primary authentication protocol used by Windows Server 2016 in Active Directory domain environments. It replaced NTLM as the default authentication method starting with Windows 2000 and provides mutual authentication, stronger security guarantees, and better scalability than its predecessor. Kerberos uses tickets issued by the […]

Read more
How to Configure Group Managed Service Accounts (gMSA) on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Group Managed Service Accounts (gMSA) on Windows Server 2016

How to Set Up Windows Server 2016 Group Managed Service Accounts Group Managed Service Accounts (gMSAs) extend the benefits of standalone Managed Service Accounts to multi-server environments. Introduced in Windows Server 2012, gMSAs are fully supported in Windows Server 2016 and allow multiple servers to share a single managed service account with automatic password rotation. […]

Read more
How to Configure Managed Service Accounts on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Managed Service Accounts on Windows Server 2016

How to Configure Windows Server 2016 Managed Service Accounts Managed Service Accounts (MSAs) were introduced in Windows Server 2008 R2 to address the administrative overhead of managing service account passwords. In Windows Server 2016, MSAs continue to provide automatic password management and simplified Service Principal Name (SPN) management for services running on a single computer. […]

Read more
How to Configure Active Directory Auditing on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Active Directory Auditing on Windows Server 2016

How to Configure Windows Server 2016 Active Directory Auditing Active Directory auditing is a critical security practice that allows administrators to track changes and access events within a Windows Server 2016 domain environment. By enabling and configuring audit policies, you can log who made changes to user accounts, group memberships, Group Policy Objects, and other […]

Read more
How to Configure Dynamic Access Control on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Dynamic Access Control on Windows Server 2016

How to Set Up Windows Server 2016 Dynamic Access Control Dynamic Access Control (DAC) is an advanced authorization framework in Windows Server 2016 that allows administrators to apply access control policies based on user attributes, device attributes, and data classification, rather than relying solely on traditional group membership and share permissions. With DAC, you can […]

Read more
How to Set Up Windows Hello for Business on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Set Up Windows Hello for Business on Windows Server 2016

How to Configure Windows Server 2016 Windows Hello for Business Windows Hello for Business (WHfB) is Microsoft’s enterprise-grade implementation of FIDO2-compatible strong authentication, replacing traditional passwords with cryptographic credentials protected by hardware (TPM) and user gestures such as PIN, fingerprint, or facial recognition. Windows Server 2016 provides the infrastructure components necessary to deploy WHfB for […]

Read more
How to Configure Microsoft Passport for Work on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Microsoft Passport for Work on Windows Server 2016

How to Set Up Windows Server 2016 Microsoft Passport Microsoft Passport, now formally named Windows Hello for Business in modern documentation, is a credential technology introduced with Windows 10 and Windows Server 2016 that replaces traditional passwords with strong two-factor authentication using public key cryptography. In the Windows Server 2016 timeframe, Microsoft Passport referred to […]

Read more
How to Configure Privileged Access Management in Active Directory on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Configure Privileged Access Management in Active Directory on Windows Server 2016

How to Configure Windows Server 2016 Privileged Access Management Privileged Access Management (PAM) is an Active Directory feature introduced with Windows Server 2016 that provides a time-based, just-in-time approach to granting privileged group memberships. Instead of users having permanent membership in groups like Domain Admins, PAM allows them to request temporary membership for the duration […]

Read more
CHAT