Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 748
  • Last Modified:

Do AD machine accounts expire?

We have a machine that is set to autologin to a network account.  It runs some equipment on our production line.  Users login to the software many times every day, but they never reboot or shutdown this machine.  It stays logged in and powered on 24/7/365.  About every 90 days, the machine loses all connection to AD and file shares. Of course this only happens during 3rd shift, when we have no one from IT in the building. The only way we can get it working again is to login as a local admin, remove it from the domain, and readd it to the domain.  Then it works for another 90 days.

Is there a way to prevent this from happening?  Will a simple reboot every 30 days alleviate this issue?

Thanks
0
hundet
Asked:
hundet
1 Solution
 
bhzdkhCommented:
0
 
snusgubbenCommented:
Machine accounts passwords don't expire from the AD side of view.

When the machine account's password is 30 days old the machine ifself will initiate a password change. The DC's never initiate the change.

If ie. a machine has been offline for 60 days and is brought back online it will change the password. No need to rejoin the domain.

Have you looked in the computers event log if something is logged when this happens?
0
 
dasaybzCommented:
Sounds to me like there is a service that is stopping.
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

 
hundetAuthor Commented:
I'm trying to get access to that machine to check eventlog.  It runs a piece of manufacturing equipment 24/7 so I'm having problems getting access.  Remote tools are shutdown by firewalls so that won't work either.

I'll post results as soon as I can get to it.
0
 
dasaybzCommented:
You can get to the event log by managing the the PC through Active Directory. Just right click on the computer account and go to manage.
0
 
hundetAuthor Commented:
No time to fully investigate this.  Production Line is too busy.  I'll deal with it in another 60 days.
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now