Solved

Do AD machine accounts expire?

Posted on 2010-09-07
6
740 Views
Last Modified: 2012-05-10
We have a machine that is set to autologin to a network account.  It runs some equipment on our production line.  Users login to the software many times every day, but they never reboot or shutdown this machine.  It stays logged in and powered on 24/7/365.  About every 90 days, the machine loses all connection to AD and file shares. Of course this only happens during 3rd shift, when we have no one from IT in the building. The only way we can get it working again is to login as a local admin, remove it from the domain, and readd it to the domain.  Then it works for another 90 days.

Is there a way to prevent this from happening?  Will a simple reboot every 30 days alleviate this issue?

Thanks
0
Comment
Question by:hundet
6 Comments
 
LVL 3

Expert Comment

by:bhzdkh
ID: 33621804
0
 
LVL 21

Accepted Solution

by:
snusgubben earned 500 total points
ID: 33621846
Machine accounts passwords don't expire from the AD side of view.

When the machine account's password is 30 days old the machine ifself will initiate a password change. The DC's never initiate the change.

If ie. a machine has been offline for 60 days and is brought back online it will change the password. No need to rejoin the domain.

Have you looked in the computers event log if something is logged when this happens?
0
 
LVL 1

Expert Comment

by:dasaybz
ID: 33628062
Sounds to me like there is a service that is stopping.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:hundet
ID: 33628190
I'm trying to get access to that machine to check eventlog.  It runs a piece of manufacturing equipment 24/7 so I'm having problems getting access.  Remote tools are shutdown by firewalls so that won't work either.

I'll post results as soon as I can get to it.
0
 
LVL 1

Expert Comment

by:dasaybz
ID: 33628395
You can get to the event log by managing the the PC through Active Directory. Just right click on the computer account and go to manage.
0
 

Author Closing Comment

by:hundet
ID: 33744714
No time to fully investigate this.  Production Line is too busy.  I'll deal with it in another 60 days.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question