?
Solved

"The security db on the srv does not have a comp acct for this wks trust...

Posted on 2013-06-13
7
Medium Priority
?
353 Views
Last Modified: 2013-06-19
have seen and solved this error several times, but this particular case is a bit unique.

Brief Background:

We used backup software to "image" a machine on the domain and chose the option to restore to dissimilar hardware. This procedure worked pretty well. We had to enter a different Win7Pro license key and re-activate other commercial products, but that was all.

A few days later, the user on the machine from which the backup image was taken is now getting the error ("The security database on the server does not have a computer account for this workstation trust relationship"). This only happens, however, if she logs into her PC as a specific domain user. She can login successfully to other PCs on the domain as this user, and others can login successfully to her machine.

Before going through the usual rigmarole to fix this error, I wanted to check with the community to see if anyone else had run into this type of problem.

My first plan would be to detach and re-join this machine to the domain.
0
Comment
Question by:ziceman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 82

Expert Comment

by:David Johnson, CD, MVP
ID: 39245493
You have two computers with the same SID.. you need to sysprep one of them
0
 

Author Comment

by:ziceman
ID: 39245556
OK. I did consider this, but we have imaged/cloned machines before without Sysprep or NewSID without running into this problem. Also, the domain controller at this site is only a Win 2003 server - certainly not the latest & greatest.

Are you certain this behavior is caused by the duplicate SID?
0
 
LVL 82

Accepted Solution

by:
David Johnson, CD, MVP earned 2000 total points
ID: 39245570
A few days later, the user on the machine from which the backup image was taken is now getting the error ("The security database on the server does not have a computer account for this workstation trust relationship").  This is what makes me believe that there is a SID problem.
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 24

Expert Comment

by:Nagendra Pratap Singh
ID: 39246592
Just you were lucky and had multiple machines with the same SID without any issues does not mean that you should carry on with this.

Sysprep is free. Let us know if you need any help with this on Windows 7 regarding usage.
0
 

Author Comment

by:ziceman
ID: 39253498
I have run Sysprep on the other machine and confirmed that they have different SIDs with PsGetSID. The individual is still having the issue. She has to unplug her PC from the LAN in order to login with her user name on her machine.

Is there another step left to perform?
0
 
LVL 82

Expert Comment

by:David Johnson, CD, MVP
ID: 39254641
remove that computer from the domain locally
in AD remove the computer account
rejoin the computer to the domain
0
 

Author Comment

by:ziceman
ID: 39256681
OK. We are almost home free on this. After removing and re-joining the domain, the machine is now able to logon with the designated user account again.

Just so I could test the operation of some of her apps/profile, she temporarily changed her password (use CTRL-ALT-DEL). When she came in the next day, she tried to change her pwd back, and it would not accept any - claiming that none met the requirements. But they definitely did - 8+ characters, etc., including the one she had used previously. She is stuck using the temp password.

I could potentially reset it manually on the DC, but really do not want to know her password.

Is this a related issue?
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question