Solved

The trust relationship between this workstation and the primary domain failed.

Posted on 2014-09-22
15
681 Views
Last Modified: 2014-09-23
Hello there,

I am getting the following error on workstation running Win7 SP1:
The trust relationship between this workstation and the primary domain failed.

I have found a lot of solutions mainly saying to unjoin and the join domain name. I was able to login to desktop when unplugin and then pluging LAN cable again.

But my main goal is to rejoin WITHOUT LOOSING the desktop and setting under that user login. I remember that one time i unjoined and joined and then I got completey new desktop.

Can you suggest more safer solution?

Regards.
0
Comment
Question by:celjan79
  • 6
  • 4
  • 4
  • +1
15 Comments
 
LVL 16

Expert Comment

by:Spike99
Comment Utility
Dropping the Pc from the domain & rejoining it is the only way to resolve that issue.
Once you rejoin the PC to the domain, the user profile info for any domain accounts should still be on the PC.
0
 

Author Comment

by:celjan79
Comment Utility
So the best thing to do is:
- unplug the LAN cable
- login to user account
- plug the LAN cable back
- unjoing from domain (joining to workgroup)
- then without restart / logoff again joing to domain
- restarting
- loging on

Is this correct?
0
 
LVL 13

Expert Comment

by:Gabriel Clifton
Comment Utility
Check DNS, especially if unplugging the network cable and putting it back in fixes the issue. DNS most of the time is the problem, but not every time. If you find NO issues with DNS then your only option is unjoin rejoin domain.
0
 

Author Comment

by:celjan79
Comment Utility
Gabriel Clifton: What do you mean regarding the DNS? I have 20 PC on the same LAN and nobody has problems with loging on.
If you mean local DNS on this machine. The internet is working, I can see network drives when plugin LAN back in. What test do you suggest?
0
 
LVL 13

Expert Comment

by:Gabriel Clifton
Comment Utility
When the system is not communicating with the domain, log into the machine locally, no domain, and check dns settings on the computer, check to ensure network is functioning properly on the computer. See if you can communicate with DC and see if the DC can communicate with the computer. Check the DNS records on your server to make sure the computer is listed properly. Check system logs to see if it is reporting what your issue is.
0
 
LVL 16

Assisted Solution

by:Spike99
Spike99 earned 250 total points
Comment Utility
Which account are you using to log on?  There's no need to unplug the network cable if you log on using a local admin account.  

Here's what I would do:
- Log on with local admin account
- join PC to a work group (call it anything you like)
- reboot when prompted
- log back on to the pc as local admin
- join the pc to the domain
- reboot when prompted
- after the PC boots back up this time, you should be able to log on to the PC with a domain user account

From my experience, DNS hasn't been the cause of failed trust relationships.  I've seen it happen when someone reset the machine's account in active directory or when someone accidentally deleted the machine account from actiive directory.  I also caused it myself one time when I accidentally gave 2 PCs the same name: I got trust failures on both machines. I had to drop both from the domain & then rejoin them both.

A few times we did get a failure of the trust relationship error when we couldn't figure out the cause, but in those cases I don't think DNS issues were to blame because there was no problem communicating with the DC at that time.
0
 

Author Comment

by:celjan79
Comment Utility
When I use local account to login (switch user option) - like "computername\user" I get the same error like before:
The trust relationship between this workstation and the primary domain failed.

Do I need to do this with LAN cable pluged out?
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 13

Expert Comment

by:Gabriel Clifton
Comment Utility
If you are using computername\user you will need to unplug, if you are using computername\Administrator you should not have to unplug, but you may need to.
0
 

Author Comment

by:celjan79
Comment Utility
So to make it clear - this should work:
- login as local administrator (user: administrator); unplug if needed
- unjoin domain by joining to workgroup
- restart
- login again as local "administrator"
- join the domain
- restart
- login as user you worked as before on that workstation

And this should result in working desktop and apps without reinstalling and resetting?
0
 
LVL 16

Expert Comment

by:Spike99
Comment Utility
That should work without re-installing. The settings for each domain user will still be there & should work again once the machine is re-joined to the domain.
0
 

Author Comment

by:celjan79
Comment Utility
When I login back with local administrator under workgroup, what user should I use to join? The user that work on that workstation and will then login or domain administrator?
0
 
LVL 13

Accepted Solution

by:
Gabriel Clifton earned 250 total points
Comment Utility
A user should not have the ability to join a domain. Use an administrator account.
0
 
LVL 2

Expert Comment

by:great_gentle_man
Comment Utility
hi,
this happened to one of my clients, few months back, used instructions in below link to resolve quickly.

http://blog.blksthl.com/2013/03/18/fix-the-trust-relationship-between-this-workstation-and-the-primary-domain-failed/
0
 

Author Closing Comment

by:celjan79
Comment Utility
Thanks for support. It worked :)
0
 
LVL 16

Expert Comment

by:Spike99
Comment Utility
Great, I'm glad we could help!

FYI for future reference, when joining a workgroup computer to a domain, you need to be logged on with a local admin account. But, when prompted, you need to enter the credentials of a domain account which has rights to join the PC to the domain.  Any member of the domain admins group will do, but other users can join up to 10 PCs to the domain.

On this page, http://technet.microsoft.com/en-us/library/cc780195(v=ws.10).aspx, MS says:
       "By default, any authenticated user has this right and can create up to 10 computer accounts in the domain."
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

First some basics on Windows 7 Backup.  It has 2 components one is a file based backup which is stored in .zip files each zip is split at around 200 Megabytes and there is the Image Backup which is as the name implies a total image of the partition …
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now