# Conneting Remote Endpoints with a On-Prem AD

**URL:** <https://openziti.discourse.group/t/conneting-remote-endpoints-with-a-on-prem-ad/815>\
**Category:** Ziti Overlay\
**Created:** [October 16, 2022, 4:59pm UTC](https://openziti.discourse.group/t/conneting-remote-endpoints-with-a-on-prem-ad/815 "2022-10-16T16:59:04Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![emoscardini](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/emoscardini/32/753_2.png) [@emoscardini](https://openziti.discourse.group/u/emoscardini)\
**Post date:** [October 18, 2022, 11:34am UTC](https://openziti.discourse.group/t/conneting-remote-endpoints-with-a-on-prem-ad/815/8 "2022-10-18T11:34:32Z")

</div>

No problem!

Also, as a troubleshooting measure, you can use this command on the client(Windows) to see if everything is working before attempting to use or join a remote domain:

```auto
Resolve-DnsName _ldap._tcp.dc._msdcs.mynet.contoso.com -Type SRV

```

In conjunction with the wildcard configuration, the ZDE(ziti-edge-tunnel) will tunnel SRV queries to the terminating end of the connection. The above command should test that & return the list of controllers that you’d use to join the AD domain. If that doesn’t work, domain services are likely to not work. Most of the time this due to a mis-configuration of the logical components or the egressing side isn’t capable of finding the DNS record requested.

---

_[View the full topic](https://openziti.discourse.group/t/conneting-remote-endpoints-with-a-on-prem-ad/815)._
