Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Friendly names of Key Admins groups aren't displayed in Windows Server 2016


View products that this article applies to.

Symptoms

In Windows Server 2016, you run the ADPREP /DOMAINPREP command to grant access to two new security principals that have the relative identifiers (RID) 526 and 527. These refer to the Key Admins and Enterprise Key Admins security groups. In this scenario, the 526 and 527 RIDs can't be resolved to friendly names until a Windows Server 2016 domain controller owns the primary domain controller (PDC) Flexible Single Master Operation (FSMO) role.

Screenshot

Additionally, both groups are given read and write access to the ms-DS-Key-Credential-Link attribute on all child objects from the domain root.

The RID 527/Enterprise Key Admins group has full control of the domain naming context (NC) head and all subordinate objects in the forest root domain and all child domains.

Screenshot 2

↑ Back to the top


Cause

Windows Server 2016 introduces new security principals. The ADPREP /DOMAINPREP command defines permissions in Active Directory partitions for different security principals

Friendly names are displayed for security principals when a computer running the operating system (OS) version that introduced them is deployed in key roles in an Active Directory forest.

Regarding default permissions assigned to the key admin groups, the intention is for that group to have delegated write access on the msdsKeyCredentialLink attribute only, which is identical to the access that the Domain Key Admins group has.   
 

↑ Back to the top


Resolution

To make the 526 and 527 security identifiers resolve to friendly names, host the PDC FSMO role on a Windows Server 2016 domain controller. To do this, you can either install a Windows Server 2016 DC as the first DC in a new forest or transfer the PDC FSMO role to a Windows Server 2016 DC.

↑ Back to the top


Keywords: kb, kbsurveynew

↑ Back to the top

Article Info
Article ID : 4033233
Revision : 11
Created on : 7/14/2017
Published on : 7/14/2017
Exists online : False
Views : 603