When I add a Windows 7 or Windows 8 PC to the domain everything goes fine for a while. At some point, however, the workstation ends up loosing track of the fact that it was joined to the domain and the network location is classified at "unidentified", instead of "domain". So, of course, the Windows firewall messes with the user and prevents them from accessing any network or Internet resources. If I disable the Windows firewall service, everything works fine. Now disabling this service isn't quite as bad, if it is a PC that is in our office. But when it is a laptop or a Surface I don't want the firewall to be off, especially when the machine travels.
I have no idea what to do to resolve this issue, short of removing it from the domain and re-adding it. The problem then is the user Profile gets totally messed up.
How do I track down the issue? It is possible it is a GPO, but how do I track down the GPO that is causing the issue. We also use ScriptLogic, so that might be impacting things as well. I'd even be willing to pay for a Microsoft support call, if I knew which number to call. Anyone have the number for MS workstation support?