mulbzh
Members-
Posts
21 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by mulbzh
-
Windows Server 2025 DCs / Trust Relationship Issues for PCs
mulbzh replied to SKELTON's topic in Windows Server 2025
after migrated clients to 25H2, no more troubles in my company ! -
I am still testing with 25H2, still no more troubles for me.... Regarding Microsoft support, the technician doesn't care about me; he deliberately makes my phone ring only once, then sends an email saying: "I tried to contact you unsuccessfully to discuss the case," and he does this just before finishing his work. Then I immediately reply to his email, and the automatic response is: "I am not currently working...".
-
i am really lost about troubles with win 2025 and trust relationship. We don't find the solution, our computers and DC are up to date but still problems. We try also migrate some computers to last 25H2, but not better. Still kerberos errors security logs with ID 4771 : Kerberos pre-authentication failed. Command reset-computerMahcinePassword resolve temporarily , with GPO to disable password machine change it is not better. replication between DC is good, DNS records OK, time sync OK, ports open OK on DC We test also nltest /sc_verify:CONTOSO.local on DC. On one DC we have error but if i look at this article this seems normal : https://www.dell.com/support/kbdoc/en-us/000226052/domain we will open ticket to Microsoft...
-
For me, i can't add new DC windows 2022 because i use new LAPS (legacy LAPS was uninstalled) and new LAPS is not available on windows 2022. I have to stay on windows 2025. I don't undertsand because staff computers works very well, no problem trust relationship but others computers have troubles. But it is the same OS version. But i sure it is because kerberos, i can see logs
-
I found this KB for 24H2 : https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb [Authentication] This update addresses an issue affecting machine password rotation in the Identity Update Manager certificate/Public Key Cryptography for Initial Authentication (PKNIT) path. This issue occurred particularly when Kerberos was used and Credential Guard was enabled, potentially causing user authentication problems. The feature Machine Accounts in Credential Gurad, which is dependent on password rotation via Kerberos, has also been disabled, until a permanent fix is made available. but i have somes computer with 23H2, i don't find KB for this version
