Fix WinRM Event ID 10154: Failed to Create WSMAN SPNs

Fix WinRM Event ID 10154: Failed to Create WSMAN SPNs

Active Directory, Identity, Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 / 2008 R2 / 2008 WinRM can log Event ID 10154 when it cannot register the WSMAN Service Principal Names (SPNs) required for Kerberos authentication. A typical event contains entries similar to: The WinRM service failed to create the following SPNs: WSMAN/server.contoso.com; WSMAN/server. In This Article 1. What Event ID 10154 Means 2. Check the Current SPNs 3. Check for Duplicate SPNs 4. Register Missing WSMAN SPNs 5. If the Error Is Access Denied 6. Why NETWORK SERVICE Is Not the AD Account 7. Verify WinRM 8. Key Takeaways 1. What Event ID 10154 Means WinRM uses SPNs for Kerberos authentication. In a normal domain configuration, the WSMAN SPNs are associated with the server's…
Read More
How to Update ESXi 4.1 to ESXi 4.1 Update 1 Without Update Manager

How to Update ESXi 4.1 to ESXi 4.1 Update 1 Without Update Manager

Archive / Legacy Topics, VMware, vSphere
Applies to: VMware ESXi 4.1 → 4.1 Update 1 Historical: This article covers the legacy VMware vSphere CLI vihostupdate.pl workflow for updating ESXi 4.1 to ESXi 4.1 Update 1 without VMware Update Manager. This method does not apply to current ESXi releases. ESXi 4.1 Update 1 was released on February 10, 2011. The original procedure used VMware vSphere CLI (vCLI) from a Windows management workstation and an offline update bundle. In This Article 1. Before You Start 2. Place the Host in Maintenance Mode 3. Install the Offline Update Bundle 4. Reboot and Verify 5. Key Takeaways 1. Before You Start Download the correct ESXi 4.1 Update 1 offline bundle for the host. Install VMware vSphere CLI (vCLI) on the management workstation. Verify network connectivity from the management workstation to…
Read More

How to Block Automatic Database Activation on an Exchange DAG Member

Exchange, Exchange Server SE / 2019 / 2016, High Availability
Applies to: Exchange Server SE / 2019 / 2016 / 2013 / 2010 In an Exchange Database Availability Group (DAG), you can prevent a Mailbox server from being selected for automatic database activation. This is useful when a DAG member should keep passive database copies but should not automatically host an active copy after a failure. The original version of this article described this as “manual failover.” A more accurate description is blocking automatic database activation on a DAG member. In This Article 1. Block Automatic Database Activation 2. What Blocked Does and Does Not Do 3. Allow Automatic Activation Again 4. Maintenance Mode Is Different 5. Key Takeaways 1. Block Automatic Database Activation To prevent database copies on a specific DAG member from being automatically activated, set the server-level…
Read More

How to Install Exchange Server Updates on DAG Members

Exchange, Exchange Server SE / 2019 / 2016, High Availability, Migration & Upgrade
Applies to: Exchange Server SE / 2019 / 2016 / 2013 / 2010 Exchange Server updates on a Database Availability Group (DAG) should be installed one member at a time. The main goal is to move active databases away from the server, prevent them from activating back during maintenance, install the update, and then return the server to production. The original version of this article was written for Exchange 2010 SP1 and used the term Update Rollup. Current Exchange Server servicing uses Cumulative Updates (CU), Security Updates (SU), and when required Hotfix Updates (HU). The DAG maintenance principle is still the same. In This Article 1. Before You Start 2. Put the DAG Member in Maintenance Mode 3. Install the Exchange Update 4. Return the Server to Production 5. Update…
Read More
How to Disable Negative DNS Caching on Windows Clients

How to Disable Negative DNS Caching on Windows Clients

Windows Client
Applies to: Windows 11 / Windows 10 / Windows 8.1 / Windows 8 / Windows 7 / Windows Vista Windows DNS clients cache both successful and unsuccessful DNS responses. A cached negative response can temporarily prevent name resolution even after the DNS record becomes available. In most cases, you should troubleshoot the DNS response and clear the resolver cache first. Disabling negative DNS caching should be used only for specific troubleshooting scenarios where cached failures are causing repeated resolution problems. In This Article 1. What Negative DNS Caching Does 2. Check the DNS Client Cache 3. Clear the DNS Cache First 4. Disable Negative DNS Caching 5. When Not to Disable It 6. Key Takeaways 1. What Negative DNS Caching Does When a DNS query returns a negative result, Windows…
Read More

How to Update Windows Server Failover Cluster Nodes Safely

Failover Clustering, Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 / 2008 R2 / 2008 / 2003 Updating a Windows Server Failover Cluster should be done one node at a time so clustered workloads remain available while each node is patched and restarted. The basic method is simple: drain roles from a node, pause it, install updates, restart it, validate it, and then return it to the cluster. The original version of this article covered service packs on Windows Server 2003, 2008, and 2008 R2. Current Windows Server versions use the same rolling-maintenance idea, but modern Failover Clustering also provides Cluster-Aware Updating (CAU) to automate much of the process. In This Article 1. Before You Start 2. Manual Rolling Update Process 3. Cluster-Aware Updating…
Read More
Fix “No Site Name Is Available for This Machine” on Exchange Server

Fix “No Site Name Is Available for This Machine” on Exchange Server

Active Directory, Exchange, Exchange Server SE / 2019 / 2016, Identity
Applies to: Exchange Server SE / 2019 / 2016 / 2013 / 2010 | Active Directory Domain Services When the Microsoft Exchange POP3 service cannot determine the Active Directory site for the server, it can fail with the following error: No site name is available for this machine. This is Windows error ERROR_NO_SITENAME (1919 / 0x77F). In most cases, the Exchange server IP subnet is missing from Active Directory Sites and Services or is mapped to the wrong AD site. In This Article 1. Check the Detected AD Site 2. Verify the Subnet in Active Directory Sites and Services 3. Correct the Subnet-to-Site Mapping 4. Validate the Fix 5. About the SiteName Registry Value 6. Key Takeaways 1. Check the Detected AD Site Run nltest /dsgetsite on the Exchange server.…
Read More
How to Uninstall Windows Internal Database (WID)

How to Uninstall Windows Internal Database (WID)

Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 / 2008 R2 / 2008 Windows Internal Database (WID) is a Windows Server feature used by roles and applications that need a local database without a separate SQL Server deployment. Windows Server Update Services (WSUS) is one common example. WID should not be removed just because an application that used it has been uninstalled. Other roles or services may still depend on the same database instance. Microsoft also warns that removing WID is generally not recommended unless you have confirmed that it is no longer required. In This Article 1. Before You Remove WID 2. Remove WID on Current Windows Server 3. WSUS-Specific Warning 4. Legacy WSUS 3.0 Method 5. Validate the Removal 6.…
Read More

How to Perform an Authoritative Restore of Active Directory Objects

Active Directory, Identity, Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 / 2008 R2 / 2008 / 2003 R2 / 2003 An authoritative restore is used when you need to recover deleted or unwantedly changed Active Directory objects from backup and make the restored copy win replication against the copies held by other domain controllers. The original version of this article described this as an “authoritative DC restore.” More precisely, the domain controller is restored from backup and selected Active Directory objects or subtrees are then marked as authoritative with ntdsutil. In This Article 1. Check Active Directory Recycle Bin First 2. When Authoritative Restore Is Needed 3. Restore the Domain Controller from Backup 4. Mark the Object as Authoritative 5. Restart and Validate Replication…
Read More