DPAPI Key Changes After Domain Restoration on Windows Server 2022

Y

Yousef Al-Awadi

Hello Microsoft Community,I am seeking guidance on an issue we encountered after restoring our Active Directory domain. Recently, our network was compromised, and malicious users managed to access our DPAPI keys. To mitigate this, we restored our domain from an old backup and migrated from Windows Server 2016 to Windows Server 2022.After the restoration, we noticed that the DPAPI keys now have a creation date of June 2024, which is more recent than the original forest creation date in 2006. We are trying to understand if this change is expected when restoring a domain on a newer server version

Continue reading...
 
Back
Top Bottom