ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Trust Relationship Between Workstation and Domain Fails – fix without double reboot

By Vladan SEGET | Last Updated: June 18, 2014

Shares

Usually it can hapend after restore operation. You restore an older VM and the Windows VM can't authenticate with the domain because the Trust Relationship between workstation and domain fails. You can see a nice error saying that “The Trust Relationship between this workstation and the primary domain failed”.

It can also happens if you restore from an older backup, which you have done on a physical system. Those backups can are usually done by imaging solutions, like the ones from Acronis (True Image) or Symantec (Norton Ghost) etc. Who do not know those, hein? But In this case also you'll face this problem with broken relationship. The default domain value is 30 days. After that each workstation do a reset of their computer account password in AD.

Now the easy way to fix this problem is probably to disjoint the workstation from the domain > reboot > and join the domain back again. Not a big deal you say, but sometimes it's not an option.

But wait there is better way. It's one liner and no need to reboot.

Trust Relationship Between Workstation and Domain Fails

In fact you can use single command to reset the computer account. You need to log into computer under account which has local admin rights.

Here is the command:

netdom resetpwd /Server:DC /UserD:Administrator /PasswordD:mysuperpassword

Trust Relationship Between Workstation and Domain Fails

Explications:

  • Server:DC is my domain controller
  • UserD:Administrator – is the user with domain admin rights
  • PasswordD:mysuperpassword – is the administrator's password

This works for server systems but also for client systems. Unfortunately if you have Windows XP for example, the Netdom command won't work because the netdom.exe isn't installed. But you can copy it from Windows server CD or iso image.. (I know additional work)…

The Netdom.exe and Nltest.exe tools are located on the Windows Server CD-ROM in the Support\Tools folder. To install these tools, run Setup.exe or extract the files from the Support.cab file

You can simply test if the secured channel has been reestablished. Just try on any domain connected workstation or server via this command:

nltest /sc_verify:lab.local

where lab.local is my lab domain….

The output looks like this:

Trust Relationship Between Workstation and Domain Fails

Now I was thinking, there must be a GPO who manages the default value of computer passwords no? Yes there is! So for my lab environment I disabled the machine password change frequency comptetely!

It's Maximum Machine Password Age and it's located at:

GPO_name\Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options

The policy name is:

Domain Member: Disable machine account password change = Disabled

It's possible to turn it off there

Domain Member: Disable machine account password change = Disabled

Now you may not want do this on your production environment, because it's a security concern. Read the Microsoft's Technet link which explains this GPO in details here.

Shares
5/5 - (8 votes)

| Filed Under: How To Tagged With: Trust Relationship Between Workstation and Domain Fails

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Comments

  1. Sim says

    June 18, 2014 at 9:26 pm

    I got around this issue specifically with snapshots by changing the computer password age to 999 days on all my templates.
    Which you can change in the registry settings:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Netlogon\Parameters]
    “Update”=”no”
    “DisablePasswordChange”=dword:00000001
    “MaximumPasswordAge”=dword:000003e7

    • Vladan SEGET says

      June 19, 2014 at 7:33 am

      Thanks for sharing.

    • John Barne says

      September 1, 2019 at 4:47 am

      Dear Sim,

      is your solution totally solve this issue? We have this issue around 30 days after we deploy pc using cloning solution.

      Thank you and appreciate your reply

  2. mikl says

    May 26, 2016 at 10:07 am

    Thanks thats what i need!
    Could you explain this statement.
    “After that each workstation do a reset of their computer account password in AD.”
    This means that the workstation itself makes the computer password reset under the built-in System account when it becomes necessary?

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in