Certain we have joined the domain correctly. There is no AD in NT4, but there is Server Manager so that is where we have added the workstation.
Main Topics
Browse All TopicsHi all,
Bit of a strange problem, but any help will be useful, as we've just spent all day getting nowhere.
We have a new vista machine which we have joined onto our NT4 domain
(Having first added the workstation to server manager and changed two local security polices -
- Domain Member: Digitally Encrypt or sign secure channel data (always) - change to disabled
- Network Security: LAN Manager authentication level - change to "Send LM and NTLM - use NTLMv2 session security if negoitated")
We now want to logon to the domain with the vista workstation, when we try to, we get the following error:
"The trust relationship between this workstation and the primary domain failed."
Now, We are pretty sure we are using the right user credentials so we are at a loss? Any help will be appreciated.
Thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
check the following link tells you a user was having a few issues like yours. turns out the order you join the domain and make the policy change son the machine has an effect on whether it joings correctly. you may need to unjoin an dthen rejoin in the process listed in the post.
let me know
http://www.petri.co.il/for
You have NetBIOS enabled on the Vista machine? This is a must, NT communicates via NetBIOS.
Do you have a NetBIOS name resolution solution in place? WINS? lmhosts? (DNS and/or hosts file does you NO good in NT)
You said that you used server manager to add the machine to the domain. Did you then join the domain from the machine? (you didn't mention that you did this - or I missed it) Just adding the object to server manager will not work.
To join the domain, try this, in this order:
1. If Windows NT Security Enhancements are installed on the PDC, ensure that they have been lowered.
2. Add the workstation to Server Manager manually.
3. Check in the local security policy on the Vista machine that "NTVLM2 responses only" is set to "LM and NTLM - use NTLMv2 session security"
4. Reboot workstation.
5. On the Vista machine Local Security Policy, disable "Domain Member: Digitally Encrypt or sign secure channel data (always)"
6. Reboot workstation.
7. On the Vista machine Local Security Policy ,Set Domain Member: Require Strong (Windows 2000 or later Session Key) to disabled.
8. Join the domain from the workstaiton.
9. Raise NTSE again on the PDC.
10. Reboot and login to the domain.
Business Accounts
Answer for Membership
by: slam69Posted on 2008-04-30 at 05:15:47ID: 21469929
doesnt sound like the domain has been joined correctly. in your ad ha sthere been a computer acount created? you may need to create it manually