Link to home
Start Free TrialLog in
Avatar of Marco Rojas
Marco Rojas

asked on

Can't change password if force to change at next log on

Hello,

We are having a very strange issue in our domain which is a mixed of Windows 2008R2 and Windows 2012R2 domain controllers.  Basically, if the user does a CRTL + ALT + Del and tries to change the password they get this error:

The security database on the server does not have a computer account for this workstation trust relationship.

This is only happening on a handful of computers (Windows 7), on one of them I tried this today:

1. Remove it from the domain
2. Deleted it from Active Directory
3. Rejoined it to the domain
4. Had user tried to change his password and got the same error listed above.

He is able to change his password on a newly imaged laptop...the logs on both the workstation and the DCs aren't giving us any indication of issues.

I am wondering if anyone has ran into this issue before?

Thank you.
Avatar of rgorman
rgorman
Flag of Canada image

Do you see any errors in the event logs on the PC's having the issue?  Are they pointing to the correct internal DNS servers for the domain?
ASKER CERTIFIED SOLUTION
Avatar of Will Szymkowski
Will Szymkowski
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Marco Rojas
Marco Rojas

ASKER

rgorman, I see a few schannel events in the system logs but nothing else that would indicate any issues.

Will, we ran a few commands to test the secure channel and they came back as good and I think that we even tried to reset it.  I will try your command next week when we get access to a laptop having that issue.

I will ask the desktop folks how they sysprep their images.

Thank you for the prompt responses guys!