# Windows Server 2016

Solutions

Contributors

Windows Server 2016 is the successor to Windows Server 2012 R2. Built upon the same core code as Windows 10, Windows Server 2016 brings enhancements in security, servicing, and connectivity. A particular focus on this release was hybrid-cloud scenarios, and has close ties to Azure and other Microsoft cloud initiatives. This does not detract from the many improvements that are available for on-premises-only deployments

Windows Server 2016 comes in Datacenter, Standard, and Essentials editions, and for servicing, has adopted windows 10's cumulative model. The new nano-server install is designed to be remotely managed and is designed to be kept current through continuous feature updates. The full GUI install operates similarly to windows 10's "Long Term Servicing Branch" (LTSB) model with cumulative security updates.

Windows Server 2016 has also shifted from a per-processor-and-CAL licensing model to a per-core-and CAL licensing model. This brings Windows Server's licensing more in line with Microsoft's other products and makes hybrid-cloud license planning easier as well.

Quick Backup of windows 2016 hyper-v server.

Can I just shut down hyper-v server . Then to copy vhdx file to a usb?
What does the double percentages before the numbers mean? "%%3%%8%%9.CRL"

CERTUTIL -SETREG CA\CRLPUBLICATIONURLS "1:%WINDIR%\SYSTEM32\CERTSRV\CERTENROLL\%%3%%8%%9.CRL\N2:http://pki.ECHOs.com/certenroll/%%3%%8%%9.crl\n10:ldap:///CN=%%7%%8,CN=%%2,CN=CDP,CN=PublicKEY SERVICES,CN=SERVICES,%%6%%10"
Hello,

I am trying to reset the local admin password for Windows Server 2K16. The only account that has access to the desktop is a basic user account so I am unable to make any changes in the GUI (lusrmgr.msc). I tried to boot to the windows recovery prompt but I can not seem to find the drive with the local os installed. Below are the following drives that I can see in recovery cmd:

A:
D:
X:

How can I get C, or the hdd with the actual os to show? I do have a \windows\system32 folder in X but there is no utilman.exe file. This is a VMWare box if that helps

We just added our first 2016 DC (FFL/DFL 2008R2) to run along with our existing 2008R2 DC.
Is there anything that will break or oddities with AD, LDAP that others might have noticed if all FSMO roles are on 2016 DC versus the 2008R2 in the scenario above.
I ask because we have noticed some strange application behaviour and it is too sporadic right now to put my finger on it.
Replication is good and no errors.
Hello All,

I am struggling with what i thought would be a simple RoboCopy script. However, I am getting some very odd behavior I have never encountered  before and I am at my wits end.

A bit about the environment the to locations are 2 server 2016 vms and are on the same subnet. Source server is a production file server and destination server test bed for program that a department is considering using. The source location contains sub folders and images mostly with about 55gb of used space. The script is triggered via a scheduled task.

@echo Off
set DirDate=%date:~-10,2%.%date:~-7,2%.%date:~-4,4%
set Name1=IMG_DB_Sync_"%DirDate%"
set Name3=IMG_DB_RoboCopy"%DirDate%"
echo ====%time% - Parameters have been set==== >>\\Source_Server\it_share$\Script_REPO\IMG_DB_Sync\LOGS\%Name1%.log ; echo ====%time% - RoboCopy Starting for Image DataBase Sync==== >>\\Source_Server\it_share$\Script_REPO\IMG_DB_Sync\LOGS\%Name1%.log
@echo Off
Robocopy /mir /S /j /R:5 /W:15 /MT:8 "\\Source_Serverr\SharedFolder$\!IMAGE DATABASE" "‪\\Dest_Server\SharedFolder$\!IMAGE DATABASE" /xf ".DS_Store" /LOG:\\Source_Server\it_share$\Script_REPO\IMG_DB_Sync\LOGS\%Name3%.log /v /ts /fp echo ====%time% - RoboCopy for IMG_DB Sync Finished==== >>\\Source_Server\it_share$\Script_REPO\IMG_DB_Sync\LOGS\%Name1%.log
;
@echo Off
echo ====%time% - Sending IMG_DB_Sync_RoboCopy log==== >>\\Source_Server\it_share\$\Script_REPO\IMG_DB_Sync\LOGS\%Name1%.log
echo ..
powershell.exe -command "& {Send-MailMessage

Issue: We had two 2008R2 Domain Controllers (AD FFL/DFL is 2008R2) that both acted as GC, DNS... I replaced one of them (DC2 - secondary DNS) with a new 2016 DC (using same name and IP, but DNS was cleaned properly and demotion of old one and promotion of new one worked flawlessly). All DNS records replicated between the remaining DC1 2008R2 and the new DC2 2016 and I do not see any replication or DNS issues in the Event logs. I now started the process of testing to replace the last 2008R2 DC (DC1) and part of the test was to turn off the existing 2008R2 DC1 and run the entire domain off the new 2016 DC2 which has all the FSMO roles on it. Everything seemed to work fine, but we experienced issues with Outlook seeing the Exchange servers as well as several application servers having issues with client application software (on W7 workstations) connecting to them. Pinging servers by name and IP worked fine, but nslookup kept insisting that it queries the DC1 which was off. So I removed the DC1 from the static network card DNS settings on the Exchange servers and Outlook managed to connect right away. I changed the priority of the DNS servers on the DNS list network card) on the application servers and as soon as I did that everything worked. I realize this was a DNS issue and know that it might take 15 min + before the workstations try for the secondary DNS server, but I am also wondering how to overcome the problem …
I am in the process of upgrading all DCs from 2008R2 to Server 2016.
On my 2nd DC (let's call it DC2) I have run into a problem - one Service Location record for the decommisioned DC will not go away.
DC2 was demoted, had its roles and features removed and was then taken out of the domain.

After removal I manually deleted the server object in Sites and Services, and cleaned up in DNS as well (the DNS is AD integrated with all DCs being DNS servers and Global Catalogs).

All DNS records stayed deleted, shot of one:
The Service Location _kerberos record representing DC2 keeps coming back - not matter how many times I delete it :-(
The record is located under "Forward Lookup Zones -> _msdcs.mydomain.name -> dc -> _sites -> Default-First-Site-Name -> _tcp -> _kerberos Service Location (SRV) [0][100][88] DC2.mydomain.name 26.10.2018 07:00:00

I did find a remnant of DC2 in the reverse lookup zone for its subnet using ADSI Edit - I deleted that record from in ADSI Edit.

It is now close to 48 hours since I deleted DC2 and I hesitate to move forward with my upgrade, because the next domain controller to be introduced into the domain will get DC2's old IP address (need to reuse the IP due to statically configured DNS server IPs on lots of hosts).

Anyone have an idea what could be causing this record the keep reappearing?
What am I missing?
I need to install a web-service related Win 2016 std / IIS server on the DMZ. We will use public SSL certificate on that. It will then query data form AD LAN SQL server.

What is the best practice to do this keeping in mind that I have read that you don't want to have AD joined servers on the DMZ?

I have installed public SSL certificates only to AD Servers and now I don't know what to do with this workgroup 2016 std server regarding public SSL certificate.

I believe tat I need to install IIS on this server.
How to disable windows store in windows 10 pro?

environment
Windows 10 pro joined to domain
Windows server 2016

I've tried to disable via gpo but nothing
Computer Configuration -> Administrative Templates -> Windows Components -> Store; in the Settings pane on the right, double click Turn off Store application, select Enabled in the properties page for the policy and click OK.
I need the best advice on setting file/folder permissions to accomplish a specific task.
I need a folder and under that folder to have subfolders of each of my users and within that folder have another folder that the users only has read only access.

If you look at the attached image
Active would be a hidden share and the user would have a shortcut on their desktop that brings them directly into Their folder , when user1 clicks the shortcut they will be in a folder that has another folder called complete and that is all they will see.  Files for them to work on will be placed in this user1 folder and when they are done either a batch file will move the files into complete or another user with access will move the files into complete. At that time user1 will be able to go into the complete folder and open the files and read them but will not be ale to modify or move the files.

In the past we had some problems with admins modifying rights on folders and inheritance really messing up our file server.

I just want to know how an expert will tackle this task.  I also had another thought that the Complete folder instead would be a shortcut that brought the user to a different directory altogether which they only have read only access,  that way I don't have to worry about inheritance from folder above and setting deny permissions on the Complete folder.

All thoughts are welcome and I think this is an easy task, just don't want to do something and in time realize I …
Can I run a Windows 2008R2 Host Terminal Server from inside a 2016 Gateway Server?
What is is legacy boot mode in windows 2016 std server?  Do I need to normal UEFI?
Any issues if I don't?
Hi

If I move a share to a different disk and reconfigure DFS replication to point to the new share. will it start working again? or do I need to resync all 3tb?
Set up a new server 2016 yesterday.
Server 2016 Clients cannot open websites when DHCP assigned.
The server is assigning the right IP's.
The only way a client get to open web pages is if i put in a public DNS IP.
I can remote control clients using teamviewer, regardless the DNS settings,

Im quite sure, that there is a problem with the setup of the server, but I cannot find out where.
I have tried running the Routing and remote access wizard.

Can anyone help?
We’ve recently had several sales people leave & replaced with new ones & I’m wondering how to handle my office licenses on my remote access server. How can I ‘free them up’ for the new users who have replaced the ones who’ve left?
Also, I’m needing to give drivers email addresses for interacting with a driver related software. These users won’t be logging onto any other servers or using any other network resources, so is there an exchange only licensing option or do they need a server license & then an exchange license on top of that?
I have a client with a 2016 RDS server using a non-standard port (not 3389) for security reasons, which works fine.
The client would like to setup a RemoteApp for it as well.  If I set the RDS server to the standard port of 33889, the remoteapp works fine, but when I change the port back to the non-standard one, I can log into the remote app wep page without issue, but when I try to start the app, I get the error;
Remote Destop can't connect to the remote computer for one of these reasons:
2 the remote computer is turned off
3 the remote computer is not available on the network

Can anyone help me get the remoteapps to work on the non-standard port?
Thanks!
Hello All;

Windows 2016 IIS ARR Load Balance Web Farm.
Containing 7 Servers in all, including "2 - IIS Servers".
(Could this be the cause of the limitation, explained below?)

OK, Running my upload file script under Windows 10 IIS, I can upload up to 20 files at one time.
Running this same script under Windows 2016 IIS, I can upload a max of 2, sometimes, 3, files at a time.
If I try to upload more than that, I get
404 Error, the page cannot be found.
So, what gives?

web.config
<system.web>
<httpRuntime maxRequestLength="1073741824" executionTimeout="3600"/>
</system.web
<system.webServer>
<security>
<requestFiltering>
<requestLimits maxAllowedContentLength="1073741824"/>
</requestFiltering>
</security>
</system.webServer>


What do I need to check on within IIS on the 2016 Server(s), to make sure they allow for more than the 2-or-3 file upload issue?

Thanks
Wayne
Hello All;

In my project, this script works perfectly on my Windows 10 IIS system.
However, running it on my Win2016 Server, it gives this error.

Exception Details: System.OverflowException: TimeSpan overflowed because the duration is too long.

On this line
Dim getDuration As String = TimeSpan.FromMinutes(Convert.ToDouble(mp3.MpegInfo.Duration)).ToString("mm\:ss")


The MP3 references this line here.
Dim mp3 As New ID3TagLibrary.MP3File(Server.MapPath("Files/" + getfile & ".mp3"))


Why would it work without any special settings under the Win10 IIS system.
Straight out of the box, on a newly installed system, it always works on the Win10.
But, not work under the Win2016 IIS System? (This is the first time being deployed under the Win2016 Server)

Any clues on this would be great.

Wayne
We currently have our print server running on server 2008 32Bit and we need to migrate it.
So can we migrate from 2008 32 bit the print server data to 2016 and if so, is there a good document showing the steps needed?
Can .NET 4.5 be installed on Windows server 2016?  If so, how?  I see that I can add 3.5 and 4.6 using "Add roles and features", but not 4.5.  (And for the record, both 3.5 and 4.6 have been installed)
Installing my first 2016 Domain Controller right now and forgot to ask how other handle updating the server (security patches from MS) without WSUS or some other form of controlling what gets installed. Is there any way to see a list similar to 2008R2 of updates available? I have used the sconfig to set it to only download updates and that seems to have worked okay (past few weeks). Should I allow the "Give me updates for other Microsoft products when I update Windows" (it is a DC -DNS,WINS, GC- but without apps like Office, etc. installed) or just go with the security updates? I am deferring feature updates!
Thanks to everyone in advance for their insights and kind assistance :-)
Much appreciated.
Please provide me with guides on where to download and how to configure HP ProLiant DL360 Generation 10 servers so I can view and configure their RAID settings within Server 2016.
I have a virtual 2016 server and I'm trying to enable NetFramework 3.5 I need service pack 1 in order to install SQL 2014.  I've tried doing this via server manager and enabling it and it fails.  I just tried DISM /Online /Enable-Feature /FeatureName:NetFx3 /All and that failed too.  Anything else I need to do.  I need to get this installed.
Windows Server 2016 Fail over Cluster Manager

Cluster Event Log:
Cluster resources " Virtual Machine APP01 of type Virtual Machine in Clustered Role "APP01" failed.

Based on the failure policies for the resources and role, the cluster service may try to bring the resource online on this node or move the group to another node of the cluster and then restart it. Check the resources and group state using Failover Cluster Manager or the Get-Cluster-Resources Windows PowerShell cmdlet.

Event ID : 1069

Any idea usually what causing this ?  it kind a generic for me
How can I check why Service Host-Local System high CPU usage? 54%....
