<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Adaxes Q&amp;A - Recent questions and answers in FAQ</title>
<link>https://www.adaxes.com/questions/qa/faq</link>
<description>Powered by Question2Answer</description>
<item>
<title>What happens when Adaxes reaches end of service for a version?</title>
<link>https://www.adaxes.com/questions/16992/what-happens-when-adaxes-reaches-end-of-service-for-version</link>
<description>&lt;p&gt;Adaxes maintains support for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;current version&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;two previous versions&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Once an Adaxes version falls outside of this window, it is considered to have reached the end of service. &lt;/p&gt;
&lt;p&gt;End‑of‑service versions no longer receive updates, including bug fixes or security patches. Any third-party changes (for example, Microsoft updates) that disrupt Adaxes functionality will &lt;strong&gt;not&lt;/strong&gt; be addressed after a version has reached the end of service.&lt;/p&gt;
&lt;p&gt;While we won't deliver new updates for end‑of‑service versions, our support team will still assist you with configuration, troubleshooting, and general usage questions regardless of how old your version of Adaxes is.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/16992/what-happens-when-adaxes-reaches-end-of-service-for-version</guid>
<pubDate>Mon, 05 Jan 2026 08:51:44 +0000</pubDate>
</item>
<item>
<title>How does Adaxes function after decommissioning the last Exchange server?</title>
<link>https://www.adaxes.com/questions/16903/does-adaxes-function-after-decommissioning-exchange-server</link>
<description>&lt;p&gt;This article is relevant to you if your organization has fully transitioned to Exchange Online and decommissioned your last on-premises Exchange server. &lt;/p&gt;
&lt;p&gt;Here are the most frequently asked questions and encountered issues.&lt;/p&gt;
&lt;hr&gt;
&lt;h4&gt;How does Adaxes work with Exchange Management Tools (EMT)?&lt;/h4&gt;
&lt;p&gt;Adaxes does not use the Exchange Management Tools, and there is no setting to force it to do so.&lt;/p&gt;
&lt;p&gt;Adaxes does not require EMT to manage mailboxes. Instead, Adaxes performs all necessary Exchange operations directly in the cloud using the Exchange Online PowerShell V3 module, provided your &lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/ManageAndAutomateOffice365/#tenant&quot;&gt;Microsoft 365 tenant is registered&lt;/a&gt; in Adaxes.&lt;/p&gt;
&lt;hr&gt;
&lt;h4&gt;Why am I seeing errors when performing Exchange operations?&lt;/h4&gt;
&lt;p&gt;If you did not fully uninstall the last Exchange server but powered it off instead, Adaxes will treat your environment as having on-premises Exchange. This happens because the information about the last Exchange server is not removed from AD if it is not uninstalled. &lt;/p&gt;
&lt;p&gt;You may see harmless error messages when performing certain Exchange operations on users with remote mailboxes. Adaxes performs the operation in Exchange Online, but also attempts to connect and run cmdlets against the missing on-premises server. The operation succeeds but you still see an error.&lt;/p&gt;
&lt;p&gt;Also, actions exclusive to on-premises Exchange, such as &lt;em&gt;Create mailbox&lt;/em&gt; and &lt;em&gt;Mail-enable&lt;/em&gt;, will remain visible in Adaxes, even though they cannot be successfully executed. Attempts to execute them will always fail.&lt;/p&gt;
&lt;hr&gt;
&lt;h4&gt;What should I configure in Adaxes?&lt;/h4&gt;
&lt;p&gt;To prevent unnecessary connection attempts to the missing server, &lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/AllowedExchangeForestsServers/#specify-forests-where-exchange-is-not-managed&quot;&gt;specify your forest as one where Exchange is not managed&lt;/a&gt; by Adaxes. You will retain the ability to manage Exchange Online mailboxes as normal.&lt;/p&gt;
&lt;p&gt;Leave &lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/EnablingDisablingRemoteMailboxes/&quot;&gt;remote mailbox settings&lt;/a&gt;, as is. Adaxes will not attempt to create remote mailboxes because you no longer need them. To provision mailboxes for new users, simply assign Exchange Online licenses to these users.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/16903/does-adaxes-function-after-decommissioning-exchange-server</guid>
<pubDate>Thu, 30 Oct 2025 11:55:40 +0000</pubDate>
</item>
<item>
<title>How does Adaxes determine account inactivity?</title>
<link>https://www.adaxes.com/questions/16835/how-does-adaxes-determine-account-inactivity</link>
<description>&lt;p&gt;Some Adaxes features calculate how long a user or computer account has been inactive. For example:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;em&gt;If is inactive &amp;lt;period&amp;gt;&lt;/em&gt; condition in business rules, scheduled tasks, and custom commands&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;adm-InactivityDuration&lt;/em&gt; calculated property&lt;/li&gt;
&lt;li&gt;The built-in &lt;em&gt;Inactive users&lt;/em&gt; and &lt;em&gt;Inactive users allowed to log in&lt;/em&gt; reports&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Adaxes always uses the same calculation method. The inactivity duration of an account is measured since the most recent of the following events.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Account creation&lt;/li&gt;
&lt;li&gt;Last sign-in&lt;/li&gt;
&lt;li&gt;Last password change or reset&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The dates of these events are pulled from specific properties, depending on whether the account is on-premises or in the cloud.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Account creation&lt;/th&gt;
&lt;th&gt;Last sign-in&lt;/th&gt;
&lt;th&gt;Last password change&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Active Directory&lt;/td&gt;
&lt;td&gt;&lt;code&gt;whenCreated&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;lastLogon&lt;/code&gt;&lt;br&gt;&lt;code&gt;lastLogonTimestamp&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;pwdLastSet&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Entra ID&lt;/td&gt;
&lt;td&gt;&lt;code&gt;createdDateTime&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;lastSignInDateTime&lt;/code&gt;&lt;br&gt;&lt;code&gt;lastNonInteractiveSignInDateTime&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;lastPasswordChangeDateTime&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;For synchronized accounts in a hybrid environment, Adaxes checks for these events in both the on-premises and cloud accounts, and picks whichever date is the most recent.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/16835/how-does-adaxes-determine-account-inactivity</guid>
<pubDate>Tue, 23 Sep 2025 09:54:53 +0000</pubDate>
</item>
<item>
<title>Why does Adaxes read the ADFS DKM key and how to prevent it?</title>
<link>https://www.adaxes.com/questions/16387/why-does-adaxes-read-the-adfs-dkm-key-and-how-to-prevent-it</link>
<description>&lt;h3&gt;Issue&lt;/h3&gt;
&lt;p&gt;The Active Directory Federation Services (ADFS) master key that decrypts ADFS certificates is stored in Active Directory, in the &lt;em&gt;thumbnailPhoto&lt;/em&gt; attribute of a contact object located in the &lt;em&gt;CN=ADFS,CN=Microsoft,CN=Program Data,DC=domain,DC=com&lt;/em&gt; container.&lt;/p&gt;
&lt;p&gt;If the &lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/ChangeManagedDomainServiceAccount/&quot;&gt;service account for your managed domain&lt;/a&gt; in Adaxes is a member of &lt;em&gt;Domain Admins&lt;/em&gt;, it will have the rights to read the DKM master key. Note that Adaxes will never attempt to access the key on its own.&lt;/p&gt;
&lt;p&gt;However, users that have the permissions to view contacts in Adaxes may be able to view the contact object where the DKM key is stored. This is especially true if you haven't modified or disabled the built-in &lt;em&gt;Domain user&lt;/em&gt; security role that grants every user the rights to view every object in your directory via Adaxes. &lt;/p&gt;
&lt;p&gt;Adaxes will not reveal the DKM key value under any circumstances, even if the user viewing the contact object has service administrator-level permissions. The attempt to view the contact will still trigger a &lt;em&gt;Suspected AD FS DKM key read&lt;/em&gt; alert though.&lt;/p&gt;
&lt;h3&gt;Solution&lt;/h3&gt;
&lt;p&gt;It is recommended to deny the &lt;em&gt;Read&lt;/em&gt; permission to your managed domain service account over the &lt;em&gt;CN=ADFS,CN=Microsoft,CN=Program Data,DC=domain,DC=com&lt;/em&gt; container via native AD access control.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/16387/why-does-adaxes-read-the-adfs-dkm-key-and-how-to-prevent-it</guid>
<pubDate>Fri, 28 Mar 2025 09:01:12 +0000</pubDate>
</item>
<item>
<title>How do I manage cloud-only users in Adaxes?</title>
<link>https://www.adaxes.com/questions/13360/how-do-i-manage-cloud-only-users-in-adaxes</link>
<description>&lt;p&gt;Starting from Adaxes 2023, you can manage Azure AD users, groups, and resource mailboxes that are not synchronized with an on-premises AD domain. However, having a registered Microsoft 365 tenant is not sufficient to view and manage cloud-only objects. You need to register your Azure AD domain. For details, see &lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/RegisterUnregisterManagedDomain/&quot;&gt;Register/unregister a managed domain&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;It is also recommended to include the entire Azure AD domain in the scope of your Microsoft 365 tenant in Adaxes.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/13360/how-do-i-manage-cloud-only-users-in-adaxes</guid>
<pubDate>Thu, 16 Feb 2023 16:56:17 +0000</pubDate>
</item>
<item>
<title>Why users cannot join computers to a domain in Adaxes if KB5020276 is installed?</title>
<link>https://www.adaxes.com/questions/13211/users-cannot-computers-domain-adaxes-kb5020276-installed</link>
<description>&lt;p&gt;If a computer has the &lt;em&gt;KB5020276 Netjoin: Domain join hardening changes&lt;/em&gt; Windows update installed, you might encounter the following error message when attempting to join such a computer to a domain via Adaxes.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;An account with the same name exists in Active Directory. Re-using the account was blocked by security policy.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The &lt;a rel=&quot;nofollow&quot; href=&quot;https://support.microsoft.com/en-au/topic/kb5020276-netjoin-domain-join-hardening-changes-2b65a0f3-1f4c-42ef-ac0f-1caaf421baf8&quot;&gt;KB5020276 security patch&lt;/a&gt; imposes additional restrictions on who can join computers to a domain. As a result, if a computer account is created via Adaxes, the user specified in the &lt;em&gt;Can be joined to domain by&lt;/em&gt; property of that account will not be able to join the computer to a domain unless one of the following scenarios is also true:&lt;/p&gt;
&lt;h3&gt;Scenario 1&lt;/h3&gt;
&lt;p&gt;The &lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/ChangeManagedDomainServiceAccount/&quot;&gt;service account for the managed domain&lt;/a&gt; is a member of &lt;em&gt;Domain Admins&lt;/em&gt; group.&lt;/p&gt;
&lt;h3&gt;Scenario 2&lt;/h3&gt;
&lt;p&gt;The computer in question has the following registry key set.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Path: HKLM\System\CurrentControlSet\Control\LSA&lt;/li&gt;
&lt;li&gt;Type: REG_DWORD&lt;/li&gt;
&lt;li&gt;Name: NetJoinLegacyAccountReuse&lt;/li&gt;
&lt;li&gt;Value: 1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Scenario 3&lt;/h3&gt;
&lt;p&gt;The user who joins the computer to a domain is explicitly specified as the primary computer owner (specified in the &lt;em&gt;ManagedBy (Primary)&lt;/em&gt; property).&lt;/p&gt;
&lt;p&gt;‎ ‎&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/13211/users-cannot-computers-domain-adaxes-kb5020276-installed</guid>
<pubDate>Fri, 20 Jan 2023 12:22:12 +0000</pubDate>
</item>
<item>
<title>How to hide the message about the temporary Microsoft 365 password assignment in the execution log?</title>
<link>https://www.adaxes.com/questions/12885/message-temporary-microsoft-password-assignment-execution</link>
<description>&lt;p&gt;By default, in hybrid environments, when an on-premises AD object is created in Adaxes within the scope of a Microsoft 365 tenant, Adaxes will &lt;a rel=&quot;nofollow&quot; href=&quot;/help/EnableDisableAzureObjectPreCreation&quot;&gt;create the corresponding object in Azure AD&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If Adaxes is configured not to synchronize passwords or a password specified for a new user does not meet password policy requirements in Azure AD, a random temporary password will be generated for that user. By default, the following message with the generated password will be displayed in the execution log:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;A temporary password has been assigned to the user's Microsoft 365 account. The temporary password is \&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;To configure Adaxes not to display this message:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Launch Adaxes Administration console.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Console Tree&lt;/em&gt;, expand the Adaxes service node.&lt;/li&gt;
&lt;li&gt;Navigate to &lt;em&gt;Configuration / Cloud Services&lt;/em&gt; and select &lt;strong&gt;Microsoft 365&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;In the Result Pane on the right, select your Microsoft 365 tenant and click &lt;strong&gt;Edit&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;On the &lt;em&gt;Tenant Details&lt;/em&gt; tab, click &lt;strong&gt;More options&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Clear the &lt;strong&gt;Display the temporary password in the Execution Log&lt;/strong&gt; checkbox.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt; twice.&lt;/li&gt;
&lt;/ol&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/12885/message-temporary-microsoft-password-assignment-execution</guid>
<pubDate>Wed, 16 Nov 2022 11:22:52 +0000</pubDate>
</item>
<item>
<title>How are Web interface language and date format selected?</title>
<link>https://www.adaxes.com/questions/10438/how-are-web-interface-language-and-date-format-selected</link>
<description>&lt;p&gt;The language of Adaxes Web interface and the format used to display dates can be different depending on the signed in user. The language can be selected either automatically or manually, whereas the regional format is always selected automatically.&lt;/p&gt;
&lt;hr&gt;
&lt;h4&gt;Language&lt;/h4&gt;
&lt;p&gt;Each user can manually choose the language of Adaxes Web interface. If a user selects a language manually, the choice is saved in their personal settings and the Web interface is always displayed for them in that language, regardless of the browser and the computer regional settings.&lt;/p&gt;
&lt;p&gt;Alternatively, users can let Adaxes automatically select their Web interface language each time they sign in. In this case, Adaxes will select the language based on the list of languages of the user's web browser. If none of the languages from the list match a language Adaxes is available in, &lt;em&gt;English (en-US)&lt;/em&gt; will be selected by default. This means that for the same user, a different Web interface language can be selected each time they sign in, depending on the browser language settings.&lt;/p&gt;
&lt;hr&gt;
&lt;h4&gt;Regional format&lt;/h4&gt;
&lt;p&gt;The format for displaying dates is selected based on the Web Interface language. If the language has multiple regional formats e.g. &lt;em&gt;English (United Kingdom)&lt;/em&gt; and &lt;em&gt;English (United States)&lt;/em&gt;, the format is selected based on the language settings set in the user's browser.&lt;/p&gt;
&lt;p&gt;For example, if the user selected &lt;em&gt;English&lt;/em&gt; as their Web interface language, and &lt;em&gt;English (United Kingdom)&lt;/em&gt; is present in their browser language list, the dates will be displayed in the &lt;em&gt;en-GB&lt;/em&gt; regional format (DD/MM/YYYY). On the other hand, if the user has &lt;em&gt;English (United States)&lt;/em&gt; in their browser language list, the dates will be displayed in the &lt;em&gt;en-US&lt;/em&gt; regional format (MM/DD/YYYY).  Finally, if the user doesn't have &lt;em&gt;English&lt;/em&gt; in their browser language list, the default regional format will be used. For the built-in languages, the default formats are: &lt;em&gt;en-US&lt;/em&gt; for English, &lt;em&gt;fr&lt;/em&gt; for French, and &lt;em&gt;de&lt;/em&gt; for German.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/10438/how-are-web-interface-language-and-date-format-selected</guid>
<pubDate>Wed, 10 Feb 2021 15:41:15 +0000</pubDate>
</item>
<item>
<title>Can I remove the Adaxes part from Web Interface URLs?</title>
<link>https://www.adaxes.com/questions/8940/can-i-remove-the-adaxes-part-from-web-interface-urls</link>
<description>&lt;p&gt;By default, Web Interface URLs look like the following: &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;http://host.company.com/Adaxes/HelpDesk&quot;&gt;http://host.company.com/Adaxes/HelpDesk&lt;/a&gt;&lt;/em&gt;. For the URLs not to contain the &lt;em&gt;Adaxes&lt;/em&gt; part:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the computer where Adaxes Web Interface is installed, launch Internet Information Services (IIS) Manager.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Connections&lt;/em&gt; pane, expand the server that hosts Adaxes Web Interface and then expand &lt;em&gt;Sites&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Select the web site that hosts Adaxes Web Interface and click &lt;strong&gt;Advanced Settings&lt;/strong&gt; in the &lt;em&gt;Actions&lt;/em&gt; pane on the right.&lt;/li&gt;
&lt;li&gt;Expand the &lt;em&gt;General&lt;/em&gt; section.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Physical Path&lt;/em&gt; field, enter the path to the &lt;strong&gt;App&lt;/strong&gt; subfolder of the folder where Adaxes Web Interface is installed which is &lt;em&gt;C:\Program Files\Softerra\Adaxes 3\Web Interface&lt;/em&gt; by default.
&lt;img src=&quot;?qa=blob&amp;amp;qa_blobid=15936205510332540858&quot; alt=&quot;image.png&quot;&gt;&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Restart IIS.&lt;/li&gt;
&lt;/ol&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/8940/can-i-remove-the-adaxes-part-from-web-interface-urls</guid>
<pubDate>Wed, 30 Oct 2019 09:40:35 +0000</pubDate>
</item>
<item>
<title>How do I redirect the default web site to the Common Sign In page?</title>
<link>https://www.adaxes.com/questions/8939/how-do-redirect-the-default-web-site-to-the-common-sign-in-page</link>
<description>&lt;p&gt;This can be setup using the HTTP Redirect option in IIS:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the computer where Adaxes Web Interface is installed, launch Internet Information Services (IIS) Manager.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Connections&lt;/em&gt; pane, expand the server that hosts Adaxes Web Interface and then expand &lt;em&gt;Sites&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Select the web site that hosts Adaxes Web Interface.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Home&lt;/em&gt; pane on the right, double-click &lt;strong&gt;HTTP Redirect&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select the &lt;strong&gt;Redirect requests to this destination&lt;/strong&gt; checkbox.&lt;/li&gt;
&lt;li&gt;In the field below, enter the URL of the Common Sign In page (e.g. &lt;em&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;http://webserver.company.com/Adaxes&quot;&gt;http://webserver.company.com/Adaxes&lt;/a&gt;&lt;/em&gt;).&lt;/li&gt;
&lt;li&gt;Clear the &lt;strong&gt;Redirect all requests to exact destination (instead of relative to destination)&lt;/strong&gt; checkbox.&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Only redirect requests to content in this directory (not subdirectories)&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Status code&lt;/em&gt; drop-down, select &lt;strong&gt;Permanent (301)&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Actions&lt;/em&gt; pane on the right, click &lt;strong&gt;Apply&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Restart IIS.&lt;/li&gt;
&lt;/ol&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/8939/how-do-redirect-the-default-web-site-to-the-common-sign-in-page</guid>
<pubDate>Wed, 30 Oct 2019 09:37:41 +0000</pubDate>
</item>
<item>
<title>How do I reset an authenticator app for a user?</title>
<link>https://www.adaxes.com/questions/8931/how-do-i-reset-an-authenticator-app-for-a-user</link>
<description>&lt;p&gt;An authenticator app can be reset for a user with the help of the &lt;em&gt;Reset multifactor authentication&lt;/em&gt; operation in Adaxes Web Interface or Administration Console. In the Web Interface, users can also use the &lt;em&gt;Change device&lt;/em&gt; option. For details, see ​&lt;a rel=&quot;nofollow&quot; href=&quot;https://www.adaxes.com/help/ConfigurePasswordSelfService/#reset-authenticator-app&quot;&gt;Reset Authenticator App&lt;/a&gt;.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/8931/how-do-i-reset-an-authenticator-app-for-a-user</guid>
<pubDate>Mon, 28 Oct 2019 13:55:08 +0000</pubDate>
</item>
<item>
<title>How to unregister an Adaxes service manually?</title>
<link>https://www.adaxes.com/questions/209/how-to-unregister-an-adaxes-service-manually</link>
<description>&lt;p&gt;Sometimes, if an Adaxes service was not uninstalled properly, Adaxes Administration Console shows the removed instance in the list of available Adaxes services.&lt;/p&gt;
&lt;p&gt;The easiest way to clear the registration information is to install Adaxes service on the same computer again, register all the domains you previously managed, and uninstall the service. If you cannot do this, read the rest of this article.&lt;/p&gt;
&lt;p&gt;Information about available Adaxes services is stored in Active Directory. To publish the information, Adaxes uses service connection points (SCPs). To clear the registration information, you need to delete appropriate SCP entries in Active Directory:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Launch Adaxes Administration console.&lt;/li&gt;
&lt;li&gt;In the Console Tree, expand your Adaxes service node, right-click &lt;em&gt;Managed Domains&lt;/em&gt;, and then click &lt;strong&gt;Find.&lt;/strong&gt; &lt;img src=&quot;?qa=blob&amp;amp;qa_blobid=3971814020065811707&quot; alt=&quot;open-find.png&quot;&gt;&lt;/li&gt;
&lt;li&gt;In the &lt;em&gt;Find&lt;/em&gt; dialog, activate the &lt;strong&gt;Criteria&lt;/strong&gt; tab. &lt;img src=&quot;?qa=blob&amp;amp;qa_blobid=3715079703445494824&quot; alt=&quot;activate-criteria.png&quot;&gt;&lt;/li&gt;
&lt;li&gt;Copy the following JSON criteria to the clipboard.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code class=&quot;language-powershell&quot;&gt;{
    &quot;objectTypes&quot;: [
        {
        &quot;type&quot;: &quot;serviceConnectionPoint&quot;,
        &quot;items&quot;: {
            &quot;type&quot;: 1,
            &quot;items&quot;: [
            {
                &quot;type&quot;: 0,
                &quot;property&quot;: &quot;keywords&quot;,
                &quot;operator&quot;: &quot;eq&quot;,
                &quot;values&quot;: [{ &quot;type&quot;: 2, &quot;value&quot;: &quot;1.3.6.1.4.1.15741.2.3.1&quot; }],
                &quot;valueLogicalOperator&quot;: 0
            }
            ],
            &quot;logicalOperator&quot;: 1
        }
        }
    ]
}&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;5&quot;&gt;
&lt;li&gt;Click &lt;strong&gt;Add criteria&lt;/strong&gt;, and in the drop-down menu click &lt;strong&gt;Paste&lt;/strong&gt;. &lt;img src=&quot;?qa=blob&amp;amp;qa_blobid=10942138988857767932&quot; alt=&quot;criteria-paste.png&quot;&gt;&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Search&lt;/strong&gt;. Adaxes will search for all the SCPs of Adaxes services in all managed Active Directory domains.&lt;/li&gt;
&lt;li&gt;Delete the SCP entries that were published by a removed Adaxes service. &lt;img src=&quot;?qa=blob&amp;amp;qa_blobid=16436029154433133504&quot; alt=&quot;delete-scp.png&quot;&gt;&lt;/li&gt;
&lt;/ol&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/209/how-to-unregister-an-adaxes-service-manually</guid>
<pubDate>Thu, 23 Aug 2012 16:54:40 +0000</pubDate>
</item>
<item>
<title>What ports does Adaxes use?</title>
<link>https://www.adaxes.com/questions/20/what-ports-does-adaxes-use</link>
<description>&lt;h3&gt;Adaxes Service&lt;/h3&gt;
&lt;p&gt;To enable communication between Adaxes service and Active Directory, the following ports (TCP and UDP) must be open for &lt;strong&gt;outgoing&lt;/strong&gt; connections on the computer where your Adaxes service is installed, and for &lt;strong&gt;incoming&lt;/strong&gt; connections on the Domain Controller(s) that you want Adaxes to connect to.  &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;389&lt;/strong&gt; LDAP - to connect to Active Directory&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;636&lt;/strong&gt; LDAP (SSL) - to connect to Active Directory via SSL&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;3268&lt;/strong&gt; LDAP - to connect to AD Global Catalog&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;3269&lt;/strong&gt; LDAP (SSL) - to connect to AD Global Catalog via SSL&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;88&lt;/strong&gt; Kerberos - for authentication&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;135&lt;/strong&gt; RPC - to resolve AD user names&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dynamic RPC ports*&lt;/strong&gt; - to communicate with Active Directory&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, to allow communication between Adaxes service and your Exchange Servers, you need to open the following ports:  &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;80&lt;/strong&gt; HTTP - if Adaxes service and Exchange are installed in the same forest&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;443&lt;/strong&gt; HTTPS - if Adaxes service and Exchange are installed in different forests&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Also, you need to allow Adaxes service to ping Active Directory domain controllers. To do this, enable &lt;strong&gt;Echo ICMP Requests&lt;/strong&gt; (ping) in the firewall settings.  &lt;/p&gt;
&lt;h3&gt;Adaxes Clients&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Adaxes Web Interface&lt;/strong&gt;, &lt;strong&gt;REST API&lt;/strong&gt;, and &lt;strong&gt;Adaxes Administration Console&lt;/strong&gt; use the following ports (TCP and UDP):  &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;389&lt;/strong&gt; LDAP - to connect to Active Directory&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;54782&lt;/strong&gt; - for communication with the Adaxes service&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If Adaxes clients are deployed in the perimeter network (DMZ), only the &lt;strong&gt;54782&lt;/strong&gt; port needs to be opened in the firewall for communication between Adaxes clients in the DMZ and Adaxes service on the intranet.&lt;/p&gt;
&lt;p&gt;If an Adaxes client is deployed in a domain that is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Not managed by Adaxes service &lt;em&gt;and&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Different from the domain where Adaxes service is deployed,&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;then you also need to open the &lt;strong&gt;3268&lt;/strong&gt; port on the computer where that Adaxes client is installed. It will be used to connect to AD Global Catalog to locate the Adaxes service.&lt;/p&gt;
&lt;p&gt;It is possible to change the port used for communication between Adaxes service and Adaxes clients (Web Interface and Administration console). For this purpose you need to change the &lt;strong&gt;port&lt;/strong&gt; attribute of the following XML element of the Adaxes service configuration file (&lt;em&gt;Softerra.Adaxes.Service.exe.Config&lt;/em&gt;):   &lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-powershell&quot;&gt;&amp;lt;configuration&amp;gt;
  ...
    &amp;lt;system.runtime.remoting&amp;gt;
    &amp;lt;customErrors mode=&quot;Off&quot; /&amp;gt;
    &amp;lt;application&amp;gt;
      &amp;lt;channels&amp;gt;
        &amp;lt;channel ref=&quot;tcp&quot; port=&quot;54782&quot; priority=&quot;2&quot; secure=&quot;true&quot;&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;em&gt;Softerra.Adaxes.Service.exe.Config&lt;/em&gt; file is located in the folder where the Adaxes Service is installed (by default, &lt;em&gt;C:\Program Files\Softerra\Adaxes 3\Service&lt;/em&gt;).  &lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;* &lt;strong&gt;To enable communication through dynamic RPC ports:&lt;/strong&gt;  &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Open the full range of dynamic RPC ports (&lt;strong&gt;1024-5000&lt;/strong&gt; for Windows 2003, &lt;strong&gt;49152-65535&lt;/strong&gt; for Windows 2008 and higher).&lt;br&gt;
&lt;strong&gt;OR&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;On Windows Server 2008 or higher, you can configure the Windows firewall to open RPC ports dynamically. If you do this there is no need to open a port range for dynamic RPC. For details, see &lt;a rel=&quot;nofollow&quot; href=&quot;http://technet.microsoft.com/en-us/library/cc732839%28WS.10%29.aspx&quot;&gt;Allowing Inbound Network Traffic that Uses Dynamic RPC&lt;/a&gt;.&lt;br&gt;
&lt;strong&gt;OR&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Explicitly specify which RPC port must be used by Active Directory, and open that port. For details, see &lt;a rel=&quot;nofollow&quot; href=&quot;http://support.microsoft.com/kb/224196&quot;&gt;Restricting Active Directory replication traffic and client RPC traffic to a specific port&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/20/what-ports-does-adaxes-use</guid>
<pubDate>Thu, 18 Nov 2010 09:51:43 +0000</pubDate>
</item>
<item>
<title>Can I configure Adaxes Web Interface to use SSL?</title>
<link>https://www.adaxes.com/questions/18/can-i-configure-adaxes-web-interface-to-use-ssl</link>
<description>&lt;p&gt;By default, SSL is not configured for the Adaxes Web Interface and network transmissions are not encrypted. However, you can configure SSL on the Adaxes Web Interface the way you do it for any other website hosted by IIS. If you configure SSL on the Adaxes Web Interface, it will work in both cases: with Windows-integrated authentication and with forms-based authentication.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/18/can-i-configure-adaxes-web-interface-to-use-ssl</guid>
<pubDate>Thu, 14 Oct 2010 13:00:03 +0000</pubDate>
</item>
<item>
<title>How Adaxes communicates with AD? Is the connection secured?</title>
<link>https://www.adaxes.com/questions/17/how-adaxes-communicates-with-ad-is-the-connection-secured</link>
<description>&lt;p&gt;Adaxes service uses the LDAP protocol to communicate with Active Directory. Interaction between the Adaxes service and Active Directory is secured for security-sensitive operations only. For example, prior to change or reset a password for an AD user, an SSL connection is established and the data are sent via an encrypted channel.  &lt;/p&gt;
&lt;p&gt;Interaction between Adaxes clients and Adaxes services is always performed using an encrypted TCP channel.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/17/how-adaxes-communicates-with-ad-is-the-connection-secured</guid>
<pubDate>Thu, 14 Oct 2010 12:58:45 +0000</pubDate>
</item>
<item>
<title>Where does Adaxes store credentials?</title>
<link>https://www.adaxes.com/questions/16/where-does-adaxes-store-credentials</link>
<description>&lt;h4&gt;Adaxes service account&lt;/h4&gt;
&lt;p&gt;Adaxes itself doesn't store the password for the Adaxes service account. Adaxes service is installed as a Windows system service that runs under the Adaxes service account.  Credentials for the system service are provided during installation and are stored by Windows.&lt;/p&gt;
&lt;hr&gt;
&lt;h4&gt;Other credentials&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Credentials for managed domains&lt;/li&gt;
&lt;li&gt;Credentials for Microsoft 365 tenants&lt;/li&gt;
&lt;li&gt;Credentials for external MS SQL logging database&lt;/li&gt;
&lt;li&gt;Credentials used in mail settings&lt;/li&gt;
&lt;li&gt;Credentials used to run PowerShell scripts &lt;em&gt;(Run As)&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Adaxes stores the above credentials in AD LDS on the computer where the Adaxes service is installed. The stored credentials are encrypted with an AES-256 &lt;em&gt;master key&lt;/em&gt;. The master key is encrypted using RSA-2048 and is also stored in AD LDS. The private RSA key that can decrypt the master key is stored locally on the computer where the Adaxes service is installed and is never transferred over the network. The key is encrypted using the Data Protection API (DPAPI) provided by Windows and can be accessed only by the Adaxes service account. To read the stored credentials, the Adaxes service decrypts its private key with the credentials of the Adaxes service account, uses the private key to decrypt the master key, and, finally, uses the master key to decrypt the stored credentials. All the encryption keys are renewed every 14 days.&lt;/p&gt;
&lt;p&gt;As the master key is required to decrypt the credentials, it must be securely exchanged between Adaxes services in a multi-server environment. To do this, the master key is encrypted separately for each Adaxes service using RSA. Here is how. &lt;/p&gt;
&lt;p&gt;When the first Adaxes service is installed, it generates the master key and a public-private key pair. The public key is published to AD LDS and the private key is stored locally. The Adaxes service then uses its own public key to encrypt the master key, and stores the encrypted master key in AD LDS. When a new Adaxes service instance is added to the configuration set, it generates its own public-private key pair and publishes the public key to AD LDS. Adaxes can recognize that a legitimate service instance is being installed using the AD LDS metadata – the information about the new service instance can be added only by AD LDS and only during Adaxes installation. Moreover, the metadata can be  accessed only by the Adaxes service account.&lt;/p&gt;
&lt;p&gt;When Adaxes detects that a new service instance is added, it encypts the master key for the new service instance with its public key, and stores the encrypted master key in AD LDS. As a result, AD LDS will contain multiple copies of the master key, each encrypted with a different public key of the corresponding Adaxes service. Each service instance can access its copy of the master key and decrypt it locally with its own private key.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/16/where-does-adaxes-store-credentials</guid>
<pubDate>Thu, 14 Oct 2010 12:50:29 +0000</pubDate>
</item>
<item>
<title>Does Softerra Adaxes extend the Active Directory schema?</title>
<link>https://www.adaxes.com/questions/13/does-softerra-adaxes-extend-the-active-directory-schema</link>
<description>&lt;p&gt;Softerra Adaxes does not extend the AD schema. Moreover, Softerra Adaxes does not store its data in Active Directory and doesn't modify the native permissions assigned in AD. If you uninstall Softerra Adaxes, you can use Active Directory just as you did before the product installation.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/13/does-softerra-adaxes-extend-the-active-directory-schema</guid>
<pubDate>Wed, 17 Jun 2009 15:39:19 +0000</pubDate>
</item>
<item>
<title>Do I have to create a trust between two domains to manage them with the same Adaxes service?</title>
<link>https://www.adaxes.com/questions/12/have-create-trust-between-domains-manage-them-adaxes-service</link>
<description>&lt;p&gt;You do not need to create a trust between AD domains to manage them with an Adaxes service. When registering an AD domain, an account with administrative permissions is specified. All operations performed via the Adaxes service in this AD domain are executed using this account. To control the user access to the managed resources, the Adaxes service uses Security Roles.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/12/have-create-trust-between-domains-manage-them-adaxes-service</guid>
<pubDate>Wed, 29 Apr 2009 12:04:43 +0000</pubDate>
</item>
<item>
<title>How can I update multiple user accounts at once?</title>
<link>https://www.adaxes.com/questions/9/how-can-i-update-multiple-user-accounts-at-once</link>
<description>&lt;p&gt;Using the Adaxes Administration Console, you can perform bulk update of AD users in several ways:  &lt;/p&gt;
&lt;p&gt;Using the Add or Modify Property Wizard:   &lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select the AD users you need in the Result Pane, Basket or search results.   &lt;/li&gt;
&lt;li&gt;Right-click the selected users and click &lt;strong&gt;Add/Modify Property&lt;/strong&gt; in the context menu.  &lt;/li&gt;
&lt;li&gt;Modify properties of the selected users the way you need.   &lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Using the Property Pages:   &lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select the AD users you need in the Result Pane, Basket or search results.   &lt;/li&gt;
&lt;li&gt;Right-click the selected users and select &lt;strong&gt;Properties&lt;/strong&gt; from the context menu.   &lt;/li&gt;
&lt;li&gt;In the Multiple Selection Properties dialog box, select the check box for the property you want to change and specify a new value for this property.   &lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt;.  &lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You can also delete or move multiple AD objects, enable or disable multiple user and computer accounts, add users or contacts to a group in bulk, etc.&lt;/p&gt;</description>
<category>FAQ</category>
<guid isPermaLink="true">https://www.adaxes.com/questions/9/how-can-i-update-multiple-user-accounts-at-once</guid>
<pubDate>Tue, 28 Apr 2009 08:43:38 +0000</pubDate>
</item>
</channel>
</rss>