We help IT Professionals succeed at work.

New podcast episode! Our very own Community Manager, Rob Jurd, gives his insight on the value of an online community. Listen Now!

x

Windows 7 Pro client causes an Application Event error 5723 - Netlogon on Domain Controller

802 Views
Last Modified: 2013-12-05
Hello,

I'm testing Windows 7 Pro clients for compatibility on my Company's network.  We are still using Windows 2000 Domain Controllers (SP4) however our Exchange Server is running on Windows 2003 R2 so we have raised the Domain Version to 2003 R2 to accommodate this as a member server (not a DC).

When can join a Windows 7 Pro client but, every time the Windows 7 computer boots up, it creates an Application Log Error in our Domain Controller (containing all the FSMO Roles).  The error is:

Event ID: 5723
Source: Netlogon

Below is the "text" of the error:
The session setup from the computer 7-TEST failed because there is no trust account in the security database for this computer. The name of the account referenced in the security database is 7-TEST$.

Thank you in advance for any assistance!
Bruce Sobo.
Comment
Watch Question

Will SzymkowskiSenior Solution Architect
CERTIFIED EXPERT
Most Valuable Expert 2015
Top Expert 2015

Commented:
You can only raise the functional level on DC's in your environment. All DC's need to be running Server 2003 in order to raise the domain functional level.

Commented:
7-TEST$ is the object's sAMAccountName in Active Directory.  For some reason the computer is not presenting its sAMAccountName with the dollar sign suffix when attempting to establish a session (during startup) with the domain contoller.

When you joined the computer to the domain did you let the computer account get created at that time or did you create the computer account ahead of time?

I would suggest removing the computer from the domain, removing the object from the domain, and re-join the computer to the domain.

Author

Commented:
Mlongoh,

When we joined the domain, we let the computer account get created - we did not create it ahead of time.

I would follow your suggestion about removing the computer from the domain and the object and re-joining the domain, but we have done this several times all with the same result.

Of course each time we used a different computer name, if fact we have used different computers entirely - same result error 5723 , Netlogon.

Thanks

Commented:
Have you attempted to create the object ahead of time before joining?

Author

Commented:
Mlongoh,

We did not try to create the object ahead of time - but we can try it - although we have never had to do this with XP clients - but I understand your line of thinking - may Windows 7 from some technical reason doesn't create the object correctly in the domain - could be Windows 7 firewall status at the time etc..

We can try it.  Also, curiously we have shut down and booted up the computer several times now and it only created the error once - when it first booted and joined the domain  - so maybe this is a bogus error.

We have an actual working PC running Windows 7 and almost everyday when it first boots it causes this error - however - there have been days it has booted and not created the error - very strange!

ALSO - I incorrectly stated that the error was in the Application Log of the Domain Controller - it's in the System Log of the Domain Controller - sorry.

Author

Commented:
Mlongoh,

Today we created the Object ahead of time (meaning the computer name in Active Directory) - same result - it generated an error.  It doesn't through the error every time it boots up and the existing PC we have running Windows 7 booted up today and didn't create an error.  I'm starting to think it is something on the Windows 7 client - either firewall blocking connection to that share when it boots or the actual share permission that our DC says it can't gain access to may need an additional permission so the DC can see it.

Thanks

Commented:
Firewall blocking connection to what share?  If you are thinking that the DC has to access any shares on the Win7 workstation I would disagree.  You can disable sharing completely and still have a PC participate in a domain without error.  So I doubt that's what your issue is.  Of course it's easily tested by disabling all firewall services on the workstation.

I suppose that it's possible that there's something on the PC blocking outbound traffic, but I doubt it.

At this point, I'd be calling Microsoft and opening a ticket.

Author

Commented:
Sorry Mlongoh - that theory was based on my limited knowledge of how the domain communicates back and forth with the work station.  I don't doubt that you know how and what data is passed between DC and work station.

I'm just taking the "literal" portion of the error - sorry
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Author

Commented:
Thanks Mlongoh - I sincerely appreciate your help.

I'm going to close this question - if I get a definitive answer for this problem - I'll let you know...

Again - thank you for your help.
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.