Windows - "The trust relationship between this workstation and the primary domain failed"

Problem

Seen on Windows clients in a domain environment.

Windows -

What's Happened?

Put simply, just like you have a password for your user account, the computer you log onto also has a password (you just never see it), it gets reset (by default) every thirty days, and all this runs in the background. For a lot of different reasons the computer password has got "Out of Sync" between the computer and the domain controller.

Solution

OK, in days of old we could mess around with netdom commands and so and so forth, now Windows 7 has replaced netdom with some Powershell that isn't much help....

1. Firstly, lets try and reset the password, on your domain controller, in administrative tools, launch "Active Directory Users and Computers" > Find the computer object that is having problems > Right click > Reset Account.

Windows -

2. Then try to login again (to be honest this usually does not work!) If it does then stop reading and have a nice day. Go back to the broken machine (Remove any network cables, and turn off Wireless etc, so it has no network connections) > Try either to login with an administrative account, or log in as the local administrator (or an account that has local administrative privileges).

Note: On Windows 7 the local administrator account is usually disabled, if you forgot the password or need it enabling you will need to do the following...

Windows Administrator "Lost Password" / "Password Reset"

Windows -

3. In the Search/Run box type sysdm.cpl {enter}.

Windows -

4. On the Computer Name tab > Change > In the workgroup section type in TEMP > OK.

Windows -

5. Take note of this Warning! - If you just logged on as the local admin then you know the password, if you DONT then reset it FIRST (Don't reboot this machine till you either know or have changed the password to a password you know). Note: To reset > Right click computer > Manage > Local Users and Groups > Users > Right click administrator > Reset Password. Warning over click OK.

Windows -

6. OK > OK > Close > Reboot.

Windows -

7. Back at the domain controller > in administrative tools, launch "Active Directory Users and Computers" > Find the computer object that is having problems > Right click > Delete.

Note: if you don't have access to the domain controller > you can rename the PC when its rebooted so it has a different computer name, if you do that then skip this step.

Windows -

8. Run sysdm.cpl again and re-join your domain again.

Windows -

9. Supply domain credentials Note: I've used the domain admin account here but a domain user can join up to 10 machines to a domain.

Windows -

10. All being well (providing the password was correct and your DNS works) you should join the domain and need to reboot again. Post reboot the computer password will be reset.

Windows -

 

Referenced from: http://www.petenetlive.com/KB/Article/0000504.htm

你可能感兴趣的:(操作技巧)