The message with Action <action> cannot be processed at the receiver, due to a ContractFilter mismatch at the EndpointDispatcher. ... This may be because of either a contract mismatch (mismatched Actions between sender and receiver) or a binding/security mismatch between the sender and the receiver.
<p>If you want to increase the number of alerts shows in report, like 100,500 or more.</p> <p>Login to AA console, then go to setting | User Option | Audit Reports | Report Result count, increase as per your need.</p>
After upgrading to AA 8.8 from AA 8.7, in the web console AD health topology never loads up. ... On web console for health, when you go to the Active Directory Topology and loading forest data all it does is keep spinning.
How to turn on and view logging within the Active Administrator. ... <ol><li>Select Settings | User Options.</li><li>Click Advanced.</li><li>By default, console logging is disabled. ... <p>Once logging is enabled, the log file can be viewed anywhere within the console by pressing the F8 key on the keyboard.</p>
How to create a custom user account locked out email alert.
We have found that if we had a trial license these features would be enabled as part of the trial, and then when choosing for instance the AD Health-only license there is no way to disable these features later.
Some GPOs do not display the correct information in the User and Domain Controller columns of the GPO History module. ... None ... Defect ID - 537530 has been created to consider including a fix in a future release of the product.
Active Administrator does not support gMSA and MSA accounts to be used as a service account to run Active Administrator services and agents.
After Domain Controllers are patched and rebooted, they stop writing to the database. ... It may not be properly installed. ... Connection String: Provider=SQL01;Server=Quest01;Database=ActiveAdministrator;Trusted_Connection=yes;
After upgrading to AA 8.6.2, audit agents keep disconnecting/connecting (disconnect for about 10 to 30 minutes) and these notifications, "The SLAgentSvc is experiencing problems writing data to the database/ The SLAgentSvc has restored its connection to the database" are being generated.
Previously in Active Administrator, the service names used for Azure AD Connect for that Active Administrator to monitor were hardcoded into the product. ... We have updated this to use a configuration file to allow the change/addition of other Azure AD / Entra services in the future as we expect Microsoft may rebrand these services again in the future.
The following error is seen when attempting to create GPO backups:<br> ... <p><img src="https://prod-support-images-cfm.s3.amazonaws.com/KB_kA06R000000HNhbSAG_4375191a.jpeg"></img></p> ... <br><br><strong>Critical Error: An error occurred while attempting to Backup GPO [NAME].<br><br>Unable to find ldifde.exe, which is a required file. ldifde.exe can be installed by adding the "AD DS Snap-Ins and Command-Line Tools" feature or by running the following PowerShell command from an elevated console: Get-WindowsCapability -Name RSAT.ActiveDirectory.DS-LDS.* -Online | Add-WindowsCapability -Online<br> at Quest.AA.AFS.ASM.GroupPolicy.LdifdeFinder.GetLdifdePath()<br> at Quest.AA.AFS.ASM.GroupPolicy.GroupPolicyProviderBase.RunLdifdeCommand(ICollection`1 arguments)<br> at Quest.AA.AFS.ASM.GroupPolicy.BackupGPOProvider.ExportDE(String domainName, String dcName, String cn, Uri backupFolder, String backupFolderName, String distinguishedName)<br> at Quest.AA.AFS.ASM.GroupPolicy.BackupGPOProvider.Backup(String domainName, Guid gpoId, BackupGpoBehavior behavior, Uri backupFolder, String gpoContainerPath)<br> at Quest.AA.AFS.ASM.GroupPolicy.GpoHistoryWatcher.ProcessGroupPolicy(Uri gpoHistoryPath, Guid gpoId, Int32 versionNumber, String domainName)<br> at Quest.AA.AFS.ASM.GroupPolicy.GpoHistoryWatcher.ProcessGroupPolicy(Guid gpoId, Int32 versionNumber, String domainName)<br> at Quest.AA.AFS.ASM.GroupPolicy.GpoHistoryWatcher.CheckForGPOChanges()</strong> Try installing the <strong>"AD DS Snap-Ins and Command-Line Tools" </strong>feature by running the following PowerShell command from an elevated console:<br><br><strong>Get-WindowsCapability -Name RSAT.ActiveDirectory.DS-LDS.* -Online | Add-WindowsCapability -Online</strong><br><br>Or, you may install it by opening Server Manager in the Active Administrator server and add the role from there.<br>
5) In the settings uncheck "Enabled" ... 6) Click "Apply to All" and "Yes" in the confirmation dialogue. ... 7) Repeat steps 4 - 6 for the other DFSRS collectors. ... There are 6 in total. ... Once this is complete the AD Health agents will no longer communicate with the replication systems on the DCs.
When using Email Settings with Exchange Online, the administrator at the top of the recipient list receives the notification correctly, while the remaining recipients configured to receive password expiration reminders receive messages with an empty email body.
When computers are removed from the Certificate Management module, the certificates associated with those computers cannot be deleted from the Certificate Repository module. ... None ... Defect ID - 534119 has been created to consider including a fix in a future release of the product.
Is it possible to audit changes to the Password Reminder module, so that alerts can be raised on any changes to this module and have access to a history showing before and after values when an option is changed?
Can we customize the email notification from AD Health? ... Like subject line by including %DomainControllerName% or the object name as mentioned within the email notification. ... No, Currently the subject and body templates for Active Directory Health are not modifiable.
How to purge stale inactive accounts. ... By default, inactive accounts are purged after 30 days of inactivity. ... You can set up a schedule, send notifications, and prevent specific users from being deleted.
When trying to remove a certificate from the Certificate Repository module, a 'NOT eligible for deletion' warning message appears: ... To remove a certificate from the Certificate Repository module, the certificate must first be removed from all the computers registered in the Certificate Management module where the certificate is present.
How to change the login and/or password for the Active Administrator services. ... Due to changes in security policies, it may become necessary to change the credential and/or the password that runs the Active Administrator services on the server where the application is installed.
<p>Can AA 8.7 support windows server 2025?</p> <p>No, AA 8.7 supports till windows server 2022. </p>
Make sure the AFS Foundation Server service account is a domain admin account that also has the Exchange Organization Management privilege.
executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)<br> at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)<br> at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()<br> at System.Threading.ThreadPoolWorkQueue.Dispatch()<br>End Dump<br><br> <p>The following steps should fix this behavior:</p>
AA Password Reminder exclusion is not working correctly. ... On the exclusions, a parent OU was excluded... but not the Child OU, looking for to have the users of the Child OU processed for them to receive the reminder.
In the GPO Search Settings module, under the User Rights Assignment category, trying to search part or the entire settings name doesn't provide any results. ... A defect has been identified in the GPO Search for User Right Assignments where results will be returned only if the searched text appears in all the User Right Assignments in all selected GPOs.
© 2025 Quest Software Inc. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center