Solved

Do AD machine accounts expire?

Posted on 2010-09-07
6
742 Views
Last Modified: 2012-05-10
We have a machine that is set to autologin to a network account.  It runs some equipment on our production line.  Users login to the software many times every day, but they never reboot or shutdown this machine.  It stays logged in and powered on 24/7/365.  About every 90 days, the machine loses all connection to AD and file shares. Of course this only happens during 3rd shift, when we have no one from IT in the building. The only way we can get it working again is to login as a local admin, remove it from the domain, and readd it to the domain.  Then it works for another 90 days.

Is there a way to prevent this from happening?  Will a simple reboot every 30 days alleviate this issue?

Thanks
0
Comment
Question by:hundet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 3

Expert Comment

by:bhzdkh
ID: 33621804
0
 
LVL 21

Accepted Solution

by:
snusgubben earned 500 total points
ID: 33621846
Machine accounts passwords don't expire from the AD side of view.

When the machine account's password is 30 days old the machine ifself will initiate a password change. The DC's never initiate the change.

If ie. a machine has been offline for 60 days and is brought back online it will change the password. No need to rejoin the domain.

Have you looked in the computers event log if something is logged when this happens?
0
 
LVL 1

Expert Comment

by:dasaybz
ID: 33628062
Sounds to me like there is a service that is stopping.
0
Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

 

Author Comment

by:hundet
ID: 33628190
I'm trying to get access to that machine to check eventlog.  It runs a piece of manufacturing equipment 24/7 so I'm having problems getting access.  Remote tools are shutdown by firewalls so that won't work either.

I'll post results as soon as I can get to it.
0
 
LVL 1

Expert Comment

by:dasaybz
ID: 33628395
You can get to the event log by managing the the PC through Active Directory. Just right click on the computer account and go to manage.
0
 

Author Closing Comment

by:hundet
ID: 33744714
No time to fully investigate this.  Production Line is too busy.  I'll deal with it in another 60 days.
0

Featured Post

Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question