Domain Controller – What Causes a Workstation to Lose Trust with the Domain Controller?

active-directorydomain-controllerworkstation-management

I've received the error several times on Windows 7 Workstations and Laptops where it loses trust with the domain controller, and I know how to fix it, but why does it do that?

Best Answer

You probably already know this, but bear with me.

Computers have passwords in AD, just like users. We don't know our computer's password, and it changes regularly via built-in logic.

The short answer is that the computer's password is no longer valid, and therefore AD doesn't trust this machine for logins any more.

Why? How? Lots of things cause this. Something interfered with the password change process, or caused the machine to revert to an old password. Possible culprits include:

  • Restoring from backup.
  • Being powered off long enough for the password to expire, followed by network issues.
  • General intermittent network issues with poor timing.
  • Viruses, malware, etc.
  • More things that aren't occurring to me at the moment, probably.

I hope that helps.