Computer account disappears after losing trust

Hello,
We are having quite a strange issue.
We have about 2000 PCs on our network running a range of different OS versions. Some PCs in randomly lose their trust with the domain.
The strange thing is, after losing the secure connectivity with the domain. The computer accounts just disappear from AD.
Is this the normal case when losing secure connectivity with the domain?
We also searched for the deleted computer account in recycle bin, But the entry is not there. Our domain and forest functional level is 2008r2 and we are running 2008 r2 standard domain controllers.
Please help me on the point "computer accounts disappearing from AD after losing trust relationship without present in deleted containers"

Hi Venkat,
Thanks for your information. We would check with the NIC drivers. But please help us to understand on the point "computer
accounts disappearing from AD after losing trust relationship without present in deleted containers" Is this a normal issue when trust relation breaks?
The disappeared objects don't even exists in active directory recycle bin after removed. This is what we see as strange.
Please help us.

Similar Messages

  • Security database on the server doesn't have a computer account for this workstation trust relationship

    Hi,
    in our windows server 2008 R2 standard , we are facing this error "Security database on the server doesn't have a computer account for this workstation trust relationship " on an regular basis. we have did below mentioned teps to solve the issue
    1. Disjoin the system from Domain & joined it again.
    2. tested the computer secure channel connection.
    3. checked the DNS settings of server
    4.checked the computer account in AD which disabled or not.
    Everything was ok but after doing changes again after 2 - 3 days we are facing same error message.
    Please help to sort the issue on an urgent basis. 

    When the error happen, can you check the computer account in your AD's console (with advanced feature at on), to check the date it was updated and if the SID is the same ? (objectSID and pwdLastset)
    I guess someone try to domain join a computer with the same name, and flush your computer account at the same time.
    Regards, Philippe
    Don't forget to mark as answer or vote as helpful to help identify good information. ( linkedin endorsement never hurt too :o) )
    Answer an interesting question ? Create a
    wiki article about it!

  • The security database on the server does not have a computer account for this workstation trust relationship

    When I try to log on to my DC it says "The security database on the server does not have a computer account for this workstation trust relationship". It won't let me log on. I installed another server server 2012r2  (its virtual )
    and I can get to ADSI edit. 
    I think what happened was I had a pc that could not connect without unplugging the network cable. So I found this fix 
    FIX: “The security database on the server does not have a computer account for this workstation trust relationship”2032011
    I’ve seen a lot of solutions, or suggestions rather, with regard to the error in the title of this post.  In my experience, the problem can almost always be resolved without extra domain add/removes and reboots, which is the most prevalent solution I have
    seen around.  Usually, this issue is due to a mismatch between attributes of the computer account in Active Directory and those values on the system itself.  Here are the steps I take to fix this issue when it crops up:
    Open up Active Directory Users & Computers pointed to the domain the computer account resides in
    From the “View” pull-down menu, make sure that “Advanced Features” is checked
    Navigate to the part of your organizational unit (OU) structure where the computer account for this server resides
    Open the Properties for the computer object
    Choose the “Attribute Editor” tab on the Properties dialog box
    Check the Attributes dNSHostName & servicePrincipalName – anywhere that a fully qualified hostname is specified (e.g. myserver.mydomainname.com), make sure that the entry matches the hostname
    you have configured when you go here on your server: Start -> Computer -> Right-Click, Properties -> Change Settings (under “Computer name, domain… settings”) -> Full Computer Name
    As an example, for a fictitious W2K8 R2 server whose Full Computer Name is “srv1.mydomainname.com”, these attribute/value pairs should be in Active Directory:
    dNSHostName:
    srv1.mydomainname.com
    servicePrincipalName:
    HOST/SRV1
    HOST/srv1.mydomainname.com
    RestrictedKrbHost/SRV1
    RestrictedKrbHost/srv1.mydomainname.com
    TERMSRV/SRV1
    TERMSRV/srv1.mydomainname.com"
    Not reading it carefully I add a computer with the same name as the pc having the issue and followed the above. The problem is that I did not notice that the spn did not want the name of my server (serv1) but the name of the trouble
    pc.
    dcdiag output
    PS C:\Users\administrator.TOM> dcdiag.exe
    Directory Server Diagnosis
    Performing initial setup:
       Trying to find home server...
       ***Error: DC3 is not a Directory Server.  Must specify /s:<Directory Server> or  /n:<Naming Context> or nothing to
       use the local machine.
       ERROR: Could not find home server.
    PS C:\Users\administrator.TOM> dcdiag.exe /s:DC2
    Directory Server Diagnosis
    Performing initial setup:
       * Identified AD Forest.
       Done gathering initial info.
    Doing initial required tests
       Testing server: Default-First-Site\DC2
          Starting test: Connectivity
             The host 9e0dca7a-d017-445a-b354-adee5ff53d48._msdcs.TOM could not be resolved to an IP address. Check the DN
             server, DHCP, server name, etc.
             Neither the the server name (DC2.TOM) nor the Guid DNS name (9e0dca7a-d017-445a-b354-adee5ff53d48._msdcs.TOM)
             could be resolved by DNS.  Check that the server is up and is registered correctly with the DNS server.
             Got error while checking LDAP and RPC connectivity. Please check your firewall settings.
             ......................... DC2 failed test Connectivity
    Doing primary tests
       Testing server: Default-First-Site\DC2
          Skipping all tests, because server DC2 is not responding to directory service requests.
       Running partition tests on : ForestDnsZones
          Starting test: CheckSDRefDom
             ......................... ForestDnsZones passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... ForestDnsZones passed test CrossRefValidation
       Running partition tests on : DomainDnsZones
          Starting test: CheckSDRefDom
             ......................... DomainDnsZones passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... DomainDnsZones passed test CrossRefValidation
       Running partition tests on : Schema
          Starting test: CheckSDRefDom
             ......................... Schema passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Schema passed test CrossRefValidation
       Running partition tests on : Configuration
          Starting test: CheckSDRefDom
             ......................... Configuration passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Configuration passed test CrossRefValidation
       Running partition tests on : TOM
          Starting test: CheckSDRefDom
             ......................... TOM passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... TOM passed test CrossRefValidation
       Running enterprise tests on : TOM
          Starting test: LocatorCheck
             ......................... TOM passed test LocatorCheck
          Starting test: Intersite
             ......................... TOM passed test Intersite
    PS C:\Users\administrator.TOM> regsvr32 schmmgmt.dll
    PS C:\Users\administrator.TOM> netdig /fix
    netdig : The term 'netdig' is not recognized as the name of a cmdlet, function, script file, or operable program.
    Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
    At line:1 char:1
    + netdig /fix
    + ~~~~~~
        + CategoryInfo          : ObjectNotFound: (netdig:String) [], CommandNotFoundException
        + FullyQualifiedErrorId : CommandNotFoundException
    PS C:\Users\administrator.TOM> Setup /PrepareSchema
    Setup : The term 'Setup' is not recognized as the name of a cmdlet, function, script file, or operable program. Check
    the spelling of the name, or if a path was included, verify that the path is correct and try again.
    At line:1 char:1
    + Setup /PrepareSchema
    + ~~~~~
        + CategoryInfo          : ObjectNotFound: (Setup:String) [], CommandNotFoundException
        + FullyQualifiedErrorId : CommandNotFoundException
    PS C:\Users\administrator.TOM> netdiag /test
    netdiag : The term 'netdiag' is not recognized as the name of a cmdlet, function, script file, or operable program.
    Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
    At line:1 char:1
    + netdiag /test
    + ~~~~~~~
        + CategoryInfo          : ObjectNotFound: (netdiag:String) [], CommandNotFoundException
        + FullyQualifiedErrorId : CommandNotFoundException
    PS C:\Users\administrator.TOM> nslooup
    nslooup : The term 'nslooup' is not recognized as the name of a cmdlet, function, script file, or operable program.
    Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
    At line:1 char:1
    + nslooup
    + ~~~~~~~
        + CategoryInfo          : ObjectNotFound: (nslooup:String) [], CommandNotFoundException
        + FullyQualifiedErrorId : CommandNotFoundException
    PS C:\Users\administrator.TOM>

    Ok fixed. 
    At a elevated cmd prompt run ;
    C:\Users\administrator.TOM>setspn -x
    As you can see the DC serv1 had duplicate SPNs.
    Checking domain DC=TOM
    Processing entry 1
    HOST/serv1.TOM is registered on these accounts:
            CN=SERV1,OU=Domain Controllers,DC=TOM
            CN=C00049,CN=Computers,DC=TOM
    {14E52635-0A95-4a5c-BDB1-E0D0C703B6C8}/TOWN-HBWJ29ZOQC is registered on these ac
    counts:
            CN=Administrator,CN=Users,DC=TOM
            CN=TOWN-HBWJ29ZOQC,CN=Computers,DC=TOM
    {14E52635-0A95-4a5c-BDB1-E0D0C703B6C8}/town-hbwj29zoqc.TOM is registered on thes
    e accounts:
            CN=Administrator,CN=Users,DC=TOM
            CN=TOWN-HBWJ29ZOQC,CN=Computers,DC=TOM
    RestrictedKrbHost/serv1 is registered on these accounts:
            CN=C00049,CN=Computers,DC=TOM
            CN=SERV1,OU=Domain Controllers,DC=TOM
    RestrictedKrbHost/serv1.TOM is registered on these accounts:
            CN=C00049,CN=Computers,DC=TOM
            CN=SERV1,OU=Domain Controllers,DC=TOM
    found 5 groups of duplicate SPNs.
    Went to the computers OU and changed computer c00049 to the correct SPN. Now I have a new issues, I'll start a new thread.

  • Old accounts disappeared after adding google account

    I have similar problem, after adding new Google account on BB, old account disappeared and all infos are taken from Google and not anymore from Outlook. Then re-created previous account and deleted Google one: no solution, re-installed BB-DTop Mng: managed to retrieve mail, notes, etc. from Outlook but the address book remains only Google one!
    How to ERASE Google presence totally?
    knottyrope wrote:
    there might be a service book that is remaining on device.
    Also you can connect to desktop manager and change default address book.
    Subject Title edited to reflect new topic.

    Did you eerase and re-install, then migrate?
    s2kip wrote:
    However, when I boot with Windows, I can see the directories of my accounts.
    Where in the directory structure are they?
    Have you looked in /Users to see if a new account was created there?

  • Accounts disappeared after re-installing Lion

    Hello,
    After re-installing Lion, my login accounts disappeared.
    I can only see the Guest account.
    However, when I boot with Windows, I can see the directories of my accounts.
    Currently, I can't login Mac OS.
    Any advise is welcomed.

    Did you eerase and re-install, then migrate?
    s2kip wrote:
    However, when I boot with Windows, I can see the directories of my accounts.
    Where in the directory structure are they?
    Have you looked in /Users to see if a new account was created there?

  • Lion server : local user account disappear after power outage

    On the server computer.After power outage I restart server the machine starts up ok.At login screen local user name disappear but there's others account same as client computer.I can log in to network account but can't log in as local.
    In sytem preference local user account is still there.
    I don't want to reinstall lion server .
    What can i do now?
    Thank you for your assistance.

    It sounds like the user directory is damaged. You might try booting into the recovery partition, running Disk Utility, and doing a Repair Volume (and maybe a repair permissions) on the server volume.

  • User account disappeared after an OS 10.4.11 update crash!

    I think the power went out during a mac update. When I started the computer again, I saw a very old desktop and all my files are missing! Everything has reverted to an older user account? The name of my user account was apple#1, but now it just says apple and does not contain any of my files created in the last year. Maybe since I upgraded to Tiger, not sure.
    Is there a way to find my missing user account or my old files! I tried some of the data recovery programs but they are very difficult to use and dont show file names.
    Any help would be appreciated,
    Thanks,
    Dan

    Dan
    I responded to your other message suggesting you open a new Topic, not realising you already had one
    And then I went away for a few days, so sorry if you felt ignored
    Did you try the commands I suggested in the other Topic?

  • Outlook email account disappeared after restarting

    Today my husband shutdown and restarted his Mac Pro as it was running slow and he hadn't turned it off for a few days. When he reopened Microsoft Outlook the entire email account was gone. He tried going back into Time Capsule to last night but nothing would work and then all the other Office programs disappeared. Apple support could only help so much, then they said to ring Microsoft. No help there, they put us onto Log Me In Rescue support and we have paid for them to try and fix it but they are having no luck at all.
    They said our system has been hacked which we didn't think could happen on a Mac. We only had POP emails set up not exchange. Can anyone offer any support at all.
    Cheers in advance

    I went back to him and this morning we had checked in the identities folder as you suggested and there was nothing in there. Checking again tonight there are files in there, but what we do with them we don't know. It could be from when to remote help people were reinstalling tonight.
    What we have just discovered, and this was not there this morning, he went into Finder and All my files. It breaks things into different sections. There was a section saying Mail and messages and there are over 13,000 items in there and all his contacts are now there. We are not sure how they got there or how to get it back to Outlook. He went to do the rebuild but there are two identity options, and we are worried about making a mistake. Not sure what is going on.
    I have spent so much time in these forums and others trying to help and I am a person that is shocking with computers. I thank you for your help so far. Still playing with it and I booked him a session at the apple store tomorrow as well.
    I just have to say how appreciative I am of the time you have given in trying to suggest solutions to our problem. There are so many people that just won't help.
    Cheers,

  • Text messages and email accounts disappeared after...

    Hi,
    I just made a backup via OVI Suite and now all my text messages and email accounts are gone. When trying to restore it skips the messages and marks them with an exclamation point inside a red triangle.
    Where did my messages and email accounts go? How will I be able to get them back?
    Please help!
    Thanks,
    Marc

    Text messages should be saved for as long as you save them. Email will be saved for the length of time you chose when you setup your mail account.
    1. Please thank those who help you by clicking the "Like" button at the bottom of the post that helped you.
    2. If your issue has been solved, please resolve it by marking the post "Solution?" which solved it for you!

  • Computer dead (sbod) after losing webDAV connection

    _The scenario:_
    To not have to put the memory card of my mobile (Nokia E70) into a card reader, use a cable or transfer several 100 MB using Bluetooth, I am using Apache (raccoon) on the mobile to supply a WebDAV service and connect my iMac 2.16 OSX 10.4.11 with this share point using WLAN. This usually works fine, my SD card is visible like any other volume on the Mac and accessible at a reasonable speed.
    _The problem:_
    a) If I forget to unmount (eject) the WebDAV drive before turning off WLAN and stopping Apache, the Mac hangs as soon as I try to do anything concerning that volume. It ask if it should eject - but it never does. It results in a spinning beach ball of death. It is also not possible to restart the computer, it seems to wait for that volume to get ejected. There is no timeout, I waited several hours. Trying to restart Finder gives the answer: Couldn't start application Finder (Error -600). Only help is to press Power for some seconds to turn the computer off hard.
    b) Accepting a) I was careful not to forget to unmount. Now there seems to be another restriction: Multiple copies at the same time also cause the bad behavior. This means my workarund doesn't help for sure.
    _The questions:_
    1) Is there a solution for my problem using Tiger? It would perfectly acceptable for me to reconnect. But I don't want to restart the Mac.
    2) Would an update to 10.5 Leopard help?

    Thank you for the fast answer.
    The cause for the problem (at least in this case) was not that a Mac went to sleep, but that the Apache server on the mobile a) was turned off by me b) didn't cope fine with more than one copy act (at least I assume it was server's fault).
    "Leopard is more forgiving" is very general, I can't judge by this statement if Leopard could help in my case. Is it more forgiving using file shares and having timeouts, or does it handle sleep mode better (this wouldn't help me at all), or does it contain changes regarding WebDAV?
    I am aware that I should run disk maintenance. But as OSX doesn't seem to have write caches without timeouts like system 7-9 had I didn't do it every time as I waited long enough before turning off. Additionally OSX already does some kind of file system check when initializing. But thank you for this hint, will do it as a precaution.
    Did search for processes that seem to hang when it happened. Didn't find it.

  • SOS! User account disappeared after password reset!

    Hi all, and I apologize for waltzing in and hollering for help like this. I have a user with a Mini running OS X 10.4.11, and this morning the user called me over because she didn't know her password. She normally would boot right into single-user, so it was odd that it asked for a pass at all. In any event we tried to figure her pass out for a while with no success, so I grabbed the OS X 10.4.6 install DVD and went to the reset password utility. I reset the pass and started up, and it gave me a login window with non usernames, just a blank username/pass option. I typed in the user's name and pass (I'd just set it not two minutes prior) and got the window shake.
    I repaired permissions and verified the disk, and went back to the reset pass util, which now says there's no user to reset the pass for on that disk!
    This would be a major disaster for me if somehow the user was deleted. Any help at all much much appreciated, if you have anything you can give me. I get notified via email immediately so I'll respond fast.

    Just an update: I went through the restore netinfo db processes, logged into single user, ran the terminal commands, and there was no network.nidb file where it was supposed to be. I ended up going old school and connecting via Target Disk Mode to another computer, copying out the user files (which were still there, thankfully) and reinstalling the whole dang thing. so, solved, I guess.

  • Aperture 3.2.4 macbookpro lion: image disappears after loading from any project; repairing everything on starting app doesn't fix it. Only restarting the computer works. Any help, please? ... in non-technical language please. Thanks

    aperture 3.2.4, macbookpro lion: image disappears after loading from any project; repairing everything on starting app doesn't fix it. Only restarting the computer works. Any help, please? ... in non-technical language please. Thanks

    “Hi Kirby, thanks a lot for your answer.
    I got one answer, from DMoore, saying:
    “Try Safe boot and then restart with only Aperture open.  Still doent work write back with more details like Ram, HD capacity/free space.  Are these thumbnails or Previews? Have you turned off building previews in AP preferances?
    Safe boot   http://support.apple.com/kb/HT1564
    Starting up into Safe Mode does several things:
    1  It forces a directory check of the startup volume.
    2  It loads only required kernel extensions (some of the items in /System/Library/Extensions).
    3  In Mac OS X v10.3.9 or earlier, Safe Mode runs only Apple-installed startup items (such items may be installed either in /Library/StartupItems or in /System/Library/StartupItems; these are different than user-selected account login items).
    4  It disables all fonts other than those in /System/Library/Fonts (Mac OS X v10.4 or later).
    5  It moves to the Trash all font caches normally stored in /Library/Caches/com.apple.ATS/(uid)/ , where (uid) is a user ID number such as 501 (Mac OS X v10.4 or later).
    6  It disables all startup items and login items (Mac OS X v10.4 or later).
    7  Mac OS X v10.5.6 or later: A Safe Boot deletes the dynamic loader shared cache at (/var/db/dyld/). A cache with issues may cause a blue screen on startup, particularly after a Software Update. Restarting normally recreates this cache.”
    As I don’t know much about the technical aspects of computers, I don’t really understand the first answer, and it sounds like following it might produce unwanted changes.
    But I understand your questions, so I’ll try to answer them;
    "loading from any Project" means that I encounter the problem when I’m using a project, possibly after/because I’ve left the Mac on overnight, and/or  I’ve made a lot of adjustments, and, once the problem is there, it happens in any other project which I open – the images load then disappear.
    I can see images in the Browser, so it only happens in the Viewer(s).
    I’m afraid I don’t understand what you mean by: “If you select "Photos" from near the top of the Library tab of the Inspector, does it show you all of your Images?”. I am a newcomer to Aperture, so I don’t know what some of the buttons are for yet, but when I want to look at and adjust my pictures, I import them, as referenced images, then Aperture creates a folder/project in the Library. When I click on that Project (when it’s working properly), all the images appear in the Browser or the Viewers  – without me needing to “select Photos from near the top of the Library tab of the Inspector”. I selected it and looked at all the items in the dropdown menu, but none of them seems to offer the option to ‘show all the images’. So I’m not sure how to answer your question except to say that – yes, I can see all the pictures in the Browser or the Viewers (when it’s working properly), but I don’t seem to need to use the Photos button to achieve this.
    Did Aperture work before?
    Yes it worked ok for a while, but I only purchased it on 24th May.
    If I understand correctly, the difference between thumbnail and preview is that the thumbnail is what I see when the “Loading” wheel is turning, and the disappearance of this wheel after a few seconds means that I am now looking at the preview (also, the thumbnail cannot be adjusted).
    So I think the problem occurs when the thumbnail has finished loading; the viewer going blank/grey might mean that it is not showing the preview.
    But I have not changed the default Preview settings in Aperture Preferences.
    My macbookpro details:
    2.7 Ghz Intel Core i7
    Memory: 8 Gb 1333 MHz DDR3
    Hard Drive capacity 499.25 GB
    Available 387.36 GB
    I have noticed another problem: I cannot apply the same rating to multiple images: following the instructions, I select a group of contiguous (or non- contiguous) images, choose a selection eg “5stars” using the keyboard, but the stars only appear in the last selected image – even though all the images are still showing as selected.”
    I hope this helps you to understand more.
    Thank you for trying to help me.
    Tony

  • I have email account that mail disappears after a day or so.

    I have email disappearing after a day or so.  I have a secod email account that the email stays on the computer.

    '''Download the [https://addons.mozilla.org/en-US/firefox/addon/searchreset/ Mozilla Search Reset]''' {web link}
    This add-on is very simple: on installation, it backs up
    and then resets your search preferences and home page
    to their default values, and then uninstalls itself. This
    affects the search bar, URL bar searches, and the home page.

  • I have an ipod nano 7th generation and can not get it recognised by my Windows 8.1 laptop (it appears briefly on My computer, then disappears). This happened after I updated iTunes to the latest version. Does that have something to do with it?

    I have an ipod nano 7th generation and can not get it recognised by my Windows 8.1 laptop (it appears briefly on My computer, then disappears). This happened after I updated iTunes to the latest version. Does that have something to do with it?

    Hello there, kiwilucea.
    The following Knowledge Base article offers up some in-depth steps for troubleshooting your issue:
    iPod not recognized in My Computer and in iTunes for Windows
    http://support.apple.com/kb/ts1369
    Keep in mind if you get to Step 12 Reinstall iTunes, those steps need to be followed exactly as outlined for the reinstall to be effective.
    Thanks for reaching out to Apple Support Communities.
    Cheers,
    Pedro.

  • My ipod shuffle disappears after I click on the icon in Itunes. I reinstalled Itunes and my computer has been updated. What else can I do?

    My ipod shuffle disappears after I click on the icon in Itunes. I reinstalled Itunes and my computer has been updated. What else can I do?

    The shuffle icon in iTunes disappears, after you click on the icon in iTunes?  If so, if you do not click on the shuffle icon in iTunes, does it remain there indefinitely?  Are you looking at the shuffle icon in the iTunes sidebar?

Maybe you are looking for

  • Shrink Log File on High Availability

    Dear support good day for you, i using SQL server 2012 and using AlwaysON High Availability (server_SQL1 = Primary & Server_SQL2=Secondary), when i try to shrink the log files he told me you must alter the database to simple recovery mode first but i

  • Urgent Help for ABAP Certification

    Hi everyone, I am planning to do certification in ABAP by Jan. Can anyone provide me the proper materials for preparing for certification. I would be grateful if anyone can help. Thanks in advance, Nitin

  • Configure FTPS sender and reciver communication channel.

    Good Morning, I am reading blog for my FTPS for secure connection: https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/964f67ec-0701-0010-bd88-f995abf4e1fc Please tell me the concept of client and server certificates server certificat

  • Is there a Text Expander-type app for the iPhone?

    Is there a Text Expander-type app for the iPhone?

  • Create a new condition type, which reference to another condition type

    I have a condition type Z002, which is reference to another condition type Z001 (Z001 is always negative, I have set the condition limit from -0.01 to -99,999,999), but with opposite sign. User need to maintain only condition record for condition typ