jamin100 Posted October 17, 2013 Posted October 17, 2013 over the past week we've had 5 machines that seem to just disappear off the domain. When we try to log on we get "there is no account in the security database to authenticate the trust with this machine" (or something similar) When we look in AD the computer account has gone ?? the only way to get them working again is to re-join them to the domain... Any ideas why this is happening?
Michael Posted October 17, 2013 Posted October 17, 2013 How many DCs do you have in the domain? And how many admin accounts, capable of deleting Computer Objects?
madurham Posted October 17, 2013 Posted October 17, 2013 We have something similar except the computer account is still in AD. We've not found a resolution as yet. We just add them to a workgroup and then back to the domain. We are thinking it may be related to how they were imaged/sysprepped.
jamin100 Posted October 17, 2013 Author Posted October 17, 2013 How many DCs do you have in the domain? And how many admin accounts, capable of deleting Computer Objects? 3 DC's and probably half a dozen accounts that could delete machines but only 2 of us that have access to any of them
jamin100 Posted October 17, 2013 Author Posted October 17, 2013 We have something similar except the computer account is still in AD. We've not found a resolution as yet. We just add them to a workgroup and then back to the domain. We are thinking it may be related to how they were imaged/sysprepped. Yeh, our machine accounts are actually being removed from AD. so we have to join the machines to a workgroup and then re-join them to the domain..
Michael Posted October 17, 2013 Posted October 17, 2013 We have something similar except the computer account is still in AD. We've not found a resolution as yet. We just add them to a workgroup and then back to the domain. We are thinking it may be related to how they were imaged/sysprepped. This is a trust issue and can be resolved with a GPP regedit: The key path should read: SYSTEM\CurrentControlSet\Services\Netlogon\Parameters 1
Michael Posted October 17, 2013 Posted October 17, 2013 3 DC's and probably half a dozen accounts that could delete machines but only 2 of us that have access to any of them And replication's working OK? Other than an account being compromised in some form, I can't see what else it could be.
jamin100 Posted October 17, 2013 Author Posted October 17, 2013 And replication's working OK? Other than an account being compromised in some form, I can't see what else it could be. yup, replication seems fine. The accounts are removed from AD on all 3 DC's. NETLOGON is replicated fine too...
jamin100 Posted October 17, 2013 Author Posted October 17, 2013 Just an update on this. When joining machines to the domain we always use just the NETBIOS domain name so for example DOMAIN. Now we are having to join them with the FQDN which is domain.school.sch.uk... Could this be possible cause / clue?
Michael Posted October 17, 2013 Posted October 17, 2013 Ever since Server 2008 this is the 'norm' with Windows Server favouring the FQDN with regards to anything. You can still add machines via NETBIOS, providing everything's setup correctly, but it wouldn't explain why 5 Computer Objects have vanished.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now