Solved

VMware Snapshot Rollback Loses Domain Identity

Posted on 2011-09-23
7
469 Views
Last Modified: 2012-06-27
I have a server running VMware ESXi 4.1.0 (free version).  On this server, I have 25 Virtual PCs created with various Operating Systems.  (Windows XP SP3, Vista SP2 32 & 64-Bit, and Windows 7 SP1 32 & 64-Bit).  These PCs are used for loading and testing software that our developers write.  The testers will take an initial Baseline snapshot of the PCs, load the software perform their testing, and then roll the snapshot back once they are ready to try another product out.  This way they have a clean slate for testing.

The problem I am experiencing is that when they roll the software back, the Virtual PCs somehow lose their Active Directory Domain identity.  You can no longer log them in with the AD usernames & passwords.  To solve the problem, I have to log in as a local admin, add the PC back to the WORKGROUP, reboot, then re-add it to AD.  Should the Snapshot not be retaining this information so I don't have to do this?
0
Comment
Question by:neptuneit
  • 5
  • 2
7 Comments
 
LVL 119
ID: 36587545
This is normal for an old snapshot.

The issues is not with the snapshot, it's with Active Directory.

0
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 36587816
The issue is similar to a VMware View Desktop issues

The machine password is stored in the Virtual Machine, It changes in Windows performs every 30 days as per policy setting and stores the machine account password retrieved from Active Directory in this virtual disk.

So you have a VM running, the machine password changes, and then you ROLLBACK the VM, which has a different machine password, and Hey Presto the passwords do not match, so the trust is broken.

See here

http://www.experts-exchange.com/Software/VMWare/Q_27116503.html
http://www.experts-exchange.com/Software/VMWare/Q_27320237.html
0
 
LVL 119
ID: 36587831
It may be better to remove these workstations from the Domain, and add to Domain when using them.

or Check the other Articles for GPO Policies, which could be applied to a Container.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 1

Author Comment

by:neptuneit
ID: 36587889
The passwords on the accounts used to log into these machines are set to never change.  So would that still apply?
0
 
LVL 119
ID: 36587969
I'm sorry I'm not discussing User Accounts.

When you Add a Workstation to a Domain, at the time it's joined, a Machine Account Password is Exchanged with the Machine. This expires every x days, set by AD!

No MACHINE ACCOUNT PASSWORD (internal on machine!).

Not user Accounts.
0
 
LVL 1

Author Comment

by:neptuneit
ID: 36587979
Okay.  I misunderstood.  That makes perfect sense.  Thanks for the feedback.
0
 
LVL 119
ID: 36588000
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article we will learn how to backup a VMware farm using Nakivo Backup & Replication. In this tutorial we will install the software on a Windows 2012 R2 Server.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Teach the user how to install log collectors and how to configure ESXi 5.5 for remote logging Open console session and mount vCenter Server installer: Install vSphere Core Dump Collector: Install vSphere Syslog Collector: Open vSphere Client: Config…
Advanced tutorial on how to run the esxtop command to capture a batch file in csv format in order to export the file and use it for performance analysis. He demonstrates how to download the file using a vSphere web client (or vSphere client) and exp…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question