Jump to content

The trust relationship between this workstation and primary domain failed.


Recommended Posts

Posted

Hi, temp at this Primary school, not sure what the last guy did exactly.

 

1) I tried to log on locally to try re-add the PC to the domain, wouldn't let me in.

 

2) Tried going into Domain Security Policy, adding the admin accounts to those who are allowed to login locally.

 

3) Looked in AD, he had removed the PC from there.

 

Any ideas into how to get into this?

 

Cheers,

Posted
normally I'd log on locally to the client, move to a fake workgroup then back to the domain.

 

That was the first initial plan, however it doesn't seem to be letting me login locally. Just says incorrect username/password (is correct).

Posted
That was the first initial plan, however it doesn't seem to be letting me login locally. Just says incorrect username/password (is correct).

 

Sounds like the password for the local account has been changed, then.

Posted
That was the first initial plan, however it doesn't seem to be letting me login locally. Just says incorrect username/password (is correct).

 

So it's fallen off the domain, he's deleted it from AD, then changed the admin pw...

 

Is there a way around this?

Posted
Time to dig out a Hiren's boot disk? Active password changer anyone... :o

 

^^ This everytime ^^ the password changer has saved my life a couple of times!

Posted
So it's fallen off the domain, he's deleted it from AD, then changed the admin pw...

 

Is there a way around this?

 

Hiren's or an XP recovery disk if you're still using XP.

 

[i love the XP exploit. :p]

Posted
normally I'd log on locally to the client, move to a fake workgroup then back to the domain.

 

You don't even need to fake move it to a workgroup, usually deleting the domain suffix (so domain.suffix.local would become just domain) from there and pressing OK will allow to rejoin it.

Posted
Just a thought which may save you from Hiren's, try logging on as .\domainadminusername and password, it may let you log on with details cached locally.
Posted
putting .\ before a username makes the machine look to its own user database, not the domain.

 

I've seen some pretty odd behaviour from this depending on local group memberships, it's worth a 30 second shot.

Posted
booted in safe mode to enable the local admin account?

 

Yup tried that, along with the .\!

 

 

Guess I'll have to go fishing with the disc!7

 

Thanks for the input guys

  • 4 months later...
Posted

Boot into a WinPE or Linux live disk, rename c:\windows\system32\utilman.exe to utilman.exe.bak then copy cmd.exe to a file called utilman.exe and reboot as normal, this will give you a command prompt with SYSTEM privileges so you can use "net use" to add an admin account and fix trust issue.

 

Then just reboot into WinPE/Linux, delete utilman.exe, rename utilman.exe.bak to utilman.exe and reboot, jobs done :)

 

Took me about 5-10 mins this way.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...