Event ID 4771: Kerberos Pre-Authentication Failed (Codes)
Event ID 4771 is a failed Kerberos pre-authentication on a domain controller. Decode failure codes 0x18, 0x12, 0x17, 0x25 and find the client IP behind lockouts.
October 7, 2026
Event ID 5805: Netlogon Session Setup Failed to Authenticate
Netlogon event ID 5805 means a computer failed to authenticate its secure channel to a DC. Find why its machine password is out of sync and repair it.
October 7, 2026
Event ID 1058: Group Policy Failed to Read gpt.ini (Fix)
Fix event ID 1058 (Group Policy failed to read gpt.ini): find the DC and path, test access, then check SYSVOL replication, DNS, the DFS client, permissions and Kerberos.
October 7, 2026
Event ID 4012 DFSR: Replicated Folder Offline Too Long (Fix)
DFSR event ID 4012 means a replicated folder was offline longer than MaxOfflineTimeInDays. Why not to raise the limit, and how to resync safely.
October 7, 2026
DFS Replication Backlog: Check It with PowerShell and Fix It
Check the DFS Replication backlog with Get-DfsrBacklog and Get-DfsrState, read the health report, and fix staging quota, sharing violations, event 2213 and 4012.
October 7, 2026
PowerShell Cheat Sheet for Windows Server Admins
PowerShell cheat sheet for Windows Server admins: services, Get-WinEvent filters, networking, firewall, disks, updates, local users, Active Directory, remoting and tasks.
October 6, 2026
Locked Out AD Users Report: PowerShell Script with Lockout Source
Free PowerShell script that lists locked-out AD users, reads event 4740 on the PDC emulator for the caller computer, and can unlock safely with -WhatIf.
October 6, 2026
AD Nested Group Membership: PowerShell Tree with Loop Detection
Free PowerShell script that shows the full nested group membership tree of an AD user or group, with paths, primary group and loop detection.
October 6, 2026
AD Privileged Group Report: Domain Admins and adminCount Audit
Free PowerShell script that reports every direct and nested member of Domain Admins and other privileged AD groups, plus adminCount=1 orphans.
October 6, 2026
BadSuccessor dMSA on Server 2025: Audit OU Rights and Patch
BadSuccessor (CVE-2025-53779) let anyone who could create a dMSA on Windows Server 2025 take over the domain. Check DC builds, audit OU rights and dMSA links, and monitor.
October 6, 2026
Export AD Users to CSV: PowerShell Script with Last Logon
Free PowerShell script that exports Active Directory users to CSV or HTML with last logon, password age, manager, department and OU.
October 6, 2026
Inactive AD Accounts Report: PowerShell Script with Safe Disable
Free PowerShell script that reports AD users and computers inactive for N days (lastLogonTimestamp), with never-logged-on detection and a safe -WhatIf disable.
October 6, 2026