Jump to content

Windows Server 2025 DCs causing trust relationship problems on client devices


Recommended Posts

Posted (edited)

Hi All

We have upgraded our 2 DCs to Windows Server 2025. We have noticed that about 20 client devices so far have been dropping off the domain and coming up with trust relationship errors when trying to login. Seems to happen when a user is already logged in as well and the user notices problems since the Radius wifi drops off which needs to be able to see AD/DCs. Did some googling and found some possible solutions but none of have worked. We have ran dcdiag on both dcs and checked replication statuses and all seems good. We dont really want to revert back to 2022 since theres 3 days worth of AD changes made. Quick fix for now is having to rejoin them to the domain but with a 1000+ devices its not ideal. Has anyone else experienced this as of yet?

 

#Nonegativevibesguys, i see you:shocked:

Edited by tayyab12
Posted (edited)

Hi there

 

We have upgraded one of our 2 DC's and have not seen any issues thus far. It was just a secondary DC that does not hold any FSMO roles, I did this as I want to make sure all is good for a month or so before contemplating doing the primary DC. I would check to make sure it is not a time sync issue you are having. Is the date/time correct on the client machines you are having issues with because if not that will be your issue. It may be related to secure time...

Edited by aac
Posted
They aren`t the most helpful with bad previous experiences and ended up fixing it ourselves with weeks of their help. Just want to see if anyone's had this issue here first.
Posted (edited)

You might be surprised with a P1 AD problem on their new shiney platform.

 

FWIW, i'd be looking to see if clients are trying to use NTLM and that is blocked on the servers, and also something around the computer default passwords which has changed (perhaps clients are blocked from changing password, and the passwords are expiring?)

 

https://learn.microsoft.com/en-us/windows-server/get-started/whats-new-windows-server-2025#:~:text=Improved%20security%20for%20default%20machine%20account%20passwords

 

https://learn.microsoft.com/en-us/windows-server/get-started/whats-new-windows-server-2025#:~:text=Legacy%20SAM%20RPC%20password%20change%20behavior

 

edit: machine passwords don't expire in versions prior to 2022+ I haven't seen any info to suggest that's changed either. But the symptoms to me do sound like an issue occurring at / after a machine changes its password....

 

So, is replication actually occurring properly between the DCs? On a problem machine, is the pwdlastset attribute the same on both domain controller?

Edited by psydii
Posted

Sorry sounds obvious but have you looked in event viewer on both DC's? Might be a clue there as to why the trust is being lost.

 

Is your domain functional level at 2016?

Posted
Functional levels been set to server 2025 both forest and domain levels. Cant seem to find anything relating to the trust relationship errors on event viewer
Posted
Hi All

We have upgraded our 2 DCs to Windows Server 2025. We have noticed that about 20 client devices so far have been dropping off the domain and coming up with trust relationship errors when trying to login. Seems to happen when a user is already logged in as well and the user notices problems since the Radius wifi drops off which needs to be able to see AD/DCs. Did some googling and found some possible solutions but none of have worked. We have ran dcdiag on both dcs and checked replication statuses and all seems good. We dont really want to revert back to 2022 since theres 3 days worth of AD changes made. Quick fix for now is having to rejoin them to the domain but with a 1000+ devices its not ideal. Has anyone else experienced this as of yet?

 

#Nonegativevibesguys, i see you:shocked:

 

What's the schema version? Here is how to check: Get-ADObject (Get-ADRootDSE).schemaNamingContext -Property objectVersion

If lower than 88 Run Adprep /ForestPrep

More here: https://www.prajwaldesai.com/upgrade-domain-controller-server-2019-2022/

Posted
[emoji638];[emoji638][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji6[emoji640][emoji637]][emoji6[emoji640][emoji637]][emoji640][emoji640][emoji640]]We dont really want to revert back to [emoji638][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji638][emoji638]

 

[emoji638];[emoji638][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji6[emoji640][emoji637]][emoji6[emoji640][emoji637]][emoji640][emoji6[emoji640][emoji638]][emoji[emoji6[emoji640][emoji638]][emoji640][emoji640]]]Functional levels been set to server [emoji638][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji638][emoji6[emoji640][emoji637]] both forest and domain levels.

 

 

You can’t roll back as you have increased the domain and forest function level. You would need to restore from a backup.

Posted (edited)

Doing both of your DC's within a week of release with no time in between upgrading each server is nuts, i'm brave but I'm not that brave (or stupid to be honest, sorry but this was gun ho!).

 

If you are using a semi decent backup software like Veeam then backup the upgraded DC's, accept the mistake (learn from it!) and restore both to before the upgrade then do an item level AD object restore from the upgraded DC backup for any new/changed objects.

 

In future this close to release of a new OS upgrade minor/non-critical servers and do them 1 at a time with a good long period in-between for testing and validation purposes.

 

Sorry to sound rude but this is just plain stupid and a hopefully a mistake you make once in your lifetime. #Nonegativevibes is giving me the impression that you are of a fairly young age / new to enterprise management and hopefully will listen to people on this thread.

 

This is why businesses have change control and test environments.

Edited by Tefters
  • Thanks 4
Posted
and restore both to before the upgrade then do an item level AD object restore from the upgraded DC backup for any new/changed objects.

 

 

This is good advice, but I would advise to get a professional in to do so.

  • Thanks 2
Posted

Pretty sure it will be some sort of machine account password change problem.

 

Probably clients not using modern methods, caused by either some misguided gpo/setting being forced from long forgotten legacy setting, or a client being well out of date (what client versions are in play?) or a bug where modern behaviours aren’t working when they should be in the October updates.

 

The other possibility is replication not working (if snapshots were used during the dc upgrade very bad things could have happened), but it could just need a nudge.

 

The final thing is something I haven’t seen in years, but some client side recovery tools used to roll back machine state to before its last machine account password change. Is there any chance this might be happening?

Posted
They aren`t the most helpful with bad previous experiences and ended up fixing it ourselves with weeks of their help. Just want to see if anyone's had this issue here first.

 

May I enquire as to your reason for upgrading the 2 most important servers so soon after release? I've not read up on 2025 too much, what features were you hoping to make use of on the DC that you dont get with a DC on 2022 for example?

 

We've got a couple of 2016 service still to upgrade to 2022 first before we look at 2025 as for example I know our DPM server if upgraded to 2025 wont be able to back them up.

Posted
sorry too seem daft but have you run DCdiag on the server?

 

Yes this is definitely a good place to start

 

What is the general consensus within the network

 

Can staff and pupils login?

 

Can they access network shares and print ?

 

Are we talking intermittent? I feel we are?

 

On a machine where you are having trust relationships can you login locally clear the even logs rebooted and see what the errors say

 

Have you changed any GPO settings if so what

Posted

thank you harold_dawg. I checked my DC server 2025 under personal certificates. There is one with the purpose of client authentication and server authentication. Do I now need to request a Kerberos certificate from my internal certification authority and store it there?

 

thank you

Posted
Not sure if this did the trick or not. I had another one this morning. But yes that is correct. The changes I made today was to make sure the backup dc was set to sync time with the PDC. I used this command: w32tm /config /syncfromflags:domhier /update I'm seeing time and DNS errors on the clients. The clients have been on the domain since June and the only change was to upgrade the backup DC to server 2025. I'm also seeing an issue on the 2025 DC with the network profile going to public instead of domain on a restart. I have to restart the NIC for it to go back to domain network profile. I have seen other posts with the same issue, even with the beta versions. I can't believe Microsoft didn't fix these bugs before general release.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...