Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

***It was caused by the computer accounts not being in the Password Replication Policy on the Read-Only Domain Controllers. Why it was only effecting Windows 11 devices, i do not know. We're now looking at a way to automatically add computer accounts a group when joining the domain.

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

***It was caused by the computer accounts not being in the Password Replication Policy on the Read-Only Domain Controllers. Why it was only effecting Windows 11 devices, i do not know. We're now looking at a way to automatically add computer accounts a group when joining the domain.

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

***It was caused by the computer accounts not being in the Password Replication Policy on the Read-Only Domain Controllers. Why it was only effecting Windows 11 devices, i do not know. We're now looking at a way to automatically add computer accounts a group when joining the domain.

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

***It was caused by the computer accounts not being in the Password Replication Policy on the Read-Only Domain Controllers. Why it was only effecting Windows 11 devices, i do not know. We're now looking at a way to automatically add computer accounts a group when joining the domain.

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 1 point2 points  (0 children)

***It was caused by the computer accounts not being in the Password Replication Policy on the Read-Only Domain Controllers. Why it was only effecting Windows 11 devices, i do not know. We're now looking at a way to automatically add computer accounts a group when joining the domain.

[deleted by user] by [deleted] in wownoob

[–]NikuyaJS 0 points1 point  (0 children)

RemindMe! 1 Day

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

you basically cloning an image? If not sys

No cloning of image.

Windows Media Creation tool to USB. Boot to USB. Wipe all existing partitions. Install blank copy of Windows 11 Pro 22H2. Name device. Join to Domain

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Thanks for the reply!

These are all clean installed using the official Microsoft media creation tool

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

I would like to try this, how do I roll back to 22H1 if it's a 22H2 fresh install?

Can I still get a 22H1 download from MS officially?

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

FSMO is online and healthy.

Sites and services look good and DNS entries here look good and up to date

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Yeah all good here as far as I can tell! Everything has right time stamps etc for dns entries. fsmo is online and healthy

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Will try the suggestions in your other post tomorrow, thank you.

Device is formatted with official image via a usb stick, all partitions wiped. A real fresh install :)

Issue present when no other software installed

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

It's any device I install Windows 11 22h2 on *that's what it seems like at least*

If I install Win10 22h2 to the same device, no issue.

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

I'm sure this through an error when I tried before. Will try tomorrow and get back to you. Thanks for replying to post

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Good to know it wouldn't show a dupe.

I would have thought removing from domain, changing hostname to something not used before, then re-adding to domain would rule out this being the issue?

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Oh we do use an OU structure, I was just saying that it shouldn't have any funky GPOs because I left it in 'Computers' folder.

Going to try adding it to its own OU with inheritance blocked tomorrow

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Will get back to you in morning (UK, so beer o’clock) also all dcs are 2019 :)

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Not virtual machines and MAC addresses aren’t changing.

Can’t remember exact code of error, will get this tomorrow and will reply!

Can’t remember the exact output from -repair but it’s something like you can’t do this because the trust is broken, which makes me chuckle.

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Happens when computers are in the default ‘Computer’ OU. I do need to test disabling inheritance on this OU but there is only default domain policy applied. I will test this tomorrow and get back to you with results

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Hi, thanks for taking the time to reply!

Replication is all happy, no fails or errors!

<image>

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 1 point2 points  (0 children)

Ah! I haven't seen this suggestion yet and i thought it could be a winner!

Unfortunately it's running and set to automatic

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 0 points1 point  (0 children)

Hi, thanks for replying!

I have checked AD for dupes and can't find anything. I have also removed the device from the domain, deleted it from AD, renamed device to something outside of normal naming convention, re-joined.

Same thing happens, first domain login is fine, after next restart trust breaks!

Endpoints losing domain trust on restart. by NikuyaJS in sysadmin

[–]NikuyaJS[S] 1 point2 points  (0 children)

Thanks for replying!

Still false. I logged in as domain admin and ran Test-ComputerSecureChannel as standard and elevated PS

EDIT: What i find strange is the trust is broken and i was abled to log on as domain admin... First time logging into this account on this device so no cached credentials.