Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi,

 

This is a strange one, hoping someone here could point me in the right direction. We run a vanilla Win08r2/Win7 network, all machines hardwired (very little wireless). We are getting random machines, every now and then, loosing their trust relationship with AD.

 

Now I know this usually happens when AD resets the computer account password but the new password isn't updated on the actual machine. And I know this happens with some laptops that are taken away from the network for extended periods of time (read weeks), so the two passwords are out of sync.

 

But this is happening to classroom desktops that never leave the school? Laptops taken away overnight and plugged back in the next morning? These machines should never lose their trust relationship with AD...

 

Any help or advice would be much appreciated.

 

Thank you.

Posted

Disable startup repair. Fixed it for us.

 

The machines where not shut down properly (kids hitting reset), doing a system restore automatically to an earlier time and then the trust was renewed.

  • Thanks 1
Posted
Have a look at this thread. We found that it was caused by machines going into startup repair (if they hadn't been shut down properly). After running the bcdedit commands on all our computers the issue doesn't seem to have re-occurred.
  • Thanks 1
Guest TheLibrarian
Posted

We have had this issue, the PC's were losing trust after (almost to the hour) 7 days.

The PC's were definitely not repairing themselves, during testing they would lose trust after a reboot (repeated reboots scripted with the Windows shutdown command).

The issue was time / date related, though where the PC's were getting their time from we didn't manage to track - it appeared that it was from each other but we didn't get chance to gather enough evidence of this unfortunately.

 

We force the DC's to allow a significant time drift - 3 hours I believe, not the best of security measures but it seems to have worked.

 

To ensure the PC's were taking their time from the DC's @sister_annex made sure the domain had a T1 time source (IIRC the DC's were quite demanding as far as the tier of the time source was concerned) and the Windows 7 clients have the following script run once on them.

 

@ECHO OFF

cls

 

 

echo, Unresgistering Time Service

net stop w32time

w32tm /unregister

echo,

 

 

echo, Registering Time Service

w32tm /register

net start w32time

echo,

 

 

echo, Setting time service for domain time

w32tm /config /syncfromflags:domhier /update

echo,

 

 

echo, Stopping Time Service

net stop w32time

echo,

 

 

echo, Starting Time Service

net start w32time

echo,

 

 

echo, PLEASE CHECK THE FOLLOWING IS CORRECT

w32tm /resync /rediscover

w32tm /query /status

echo,

 

 

Pause

Posted
Thanks guys, I think you may have something with the "going in to repair after not shutting down properly". I'll check out disabling repair.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...