Link to home
Start Free TrialLog in
Avatar of cosmicIPA
cosmicIPAFlag for United States of America

asked on

After restoring SBS2011 from an old image, networked computers can't connect.

After restoring SBS2011 from old image, other computers can't connect. What is the best way to fix the secure channel problem without removing and rejoining computers?
Avatar of Cliff Galiher
Cliff Galiher
Flag of United States of America image

If the image was old, disjoining and rejoining is the only way.
You gonna have to disjoin and rejoin machines unfortunately
Surprised that is the case.  Based on your previous question I would assume the restore was only a few days old?  I assume you have reboot the client machines after the restore?  Otherwise as Cliff stated you need to disjoin and rejoin.  Users profiles should not be affected.
Avatar of cosmicIPA

ASKER

Isn't there a way to reset the SID or within AD? I found "Reset the Account" In AD UC > domain.local > MyBusiness > Computers > SBSComputers by right-clicking the computer and have an option to Reset Account.
 What does this do? Would this allow computers to re-join without un-joining the computer to the domain? (fingers crossed, ha).
No. It alleviates needing to delete the object from AD before rejoining, which is desirable in, organizations where an object may have data worth keeping (such as bitlocker keys.)  If reset, a disjoin/rejoin reconnects the computer to the existing object. But does not alleviate the need to do the rejoin process to establish a new secure channel.
Only option is to join them again, the SID is created by the join process. This way you will sleep better knowing they are setup correctly. Those that have tried changing the SID (comparable to russian roulette) have regreted it, so rejoining is a time saver. Best of luck
When I try to login as local Administrator to disjoin/rejoin I get: "The trust relationship between this workstation and the primary domain has failed."
Are you sure it is a local account?  Try username = PCname\UserName,
Hi Rob, Indeed it is the local account entered as you suggested...
Ok, I discovered the issue was because I used the domain name as a workgroup name. After I changed it "workgroup" it functioned correctly and let me rejoin.
However on SOME computers I receive the message when attempting to connect using the local PCname\UserName:  

" There are no logon servers available to service the logon request"...

Those I have restored an image but my question is why does it not just recognize the local account?
That is usually a DNS error when a domain account cannot access Active Directory.  Odd you are getting that with a local account.  Out of curiosity, try logging in with the machine physically disconnected from the network.
Hi everybody. Whew, what a long weekend of disjoining and re-joining computers. All of them connected ok, had access to shares and everything seemed to be functioning properly but alas some computers after a restart I receive the "can't find the logon server" message. I can remotely connect to the problem computer with TeamViewer as admin, but locally get the message. Must be the AD. Well today is going to be another long one...
ASKER CERTIFIED SOLUTION
Avatar of Rob Williams
Rob Williams
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you Cliff, Rob, Edward and Vince for all you help, I REALLY REALLY appreciated it! The Network is back up and nominal. Thanks again, you guys rock.
Eric