QuestionQ40

Deploy and manage AD DS

Overview

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

Existing environment

The domain contains a domain controller named DC1 and a member server named Server1.

Issue

Users cannot sign in to Server1 by using domain credentials and receive the following error message:

The trust relationship between this workstation and the primary domain failed.

Requirement

You need to restore domain authentication on Server1 without removing Server1 from the domain.

Solution: On Server1, you run Set-ADAccountPassword -Identity “Server1$” -Reset.

Does this achieve the goal?

Explanation

A computer trust failure requires the local machine-account secret and the Active Directory computer-account password to be synchronized. Set-ADAccountPassword -Reset updates the password for the computer account in Active Directory only; it does not update Server1's local machine password or repair its secure channel. A machine-password or secure-channel repair operation, such as Reset-ComputerMachinePassword or Test-ComputerSecureChannel -Repair, is required.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!