FLS Internal: Broken AD trust relationship and how to fix it

Summary:

Computers that are joined to the UNH network have passwords for AD (similar to a security certificate). This password is only known to the computer and Active Directory.

It is possible for these passwords to expire or to become corrupted via malware or other network issues.

Fix:

This work-flow is for Windows machines only.

In order to fix this, you will need local administrator information for the computer in question.

~~ Log in as local admin ~~

 

Take the computer off the domain (move to 'workgroup')

  1. In the Local Admin account, Go to: Control Panel > System >

 

Control Pannel

 

  1. Under Computer name, domain, and workgroup settings: select Change Settings

 

Windows 10 edit domain and workgroup settings

  1. Copy down the old computer name (document in TD)

  2. Select "Workgroup" and select "OK" (this will require local admin password)

 

  1. Restart the computer, it should no longer be on the domain. (you can check this with the 1st 2 steps)

 

Join the computer to the domain

Same process but in step 4 select Domain and enter "ad.unh.edu"

Minimally change the name and press "OK"

Restart and you should be able to log on with an AD account

 

+--- unresolved questions ---+

need to find out the default behavior of new devices added to AD, what follow up needs to happen?

Does not go into a useful OU, how will ET&S deal with that?

*do you need to change the name of the device? --> YES to avoid name duplication in AD.

+---     ---+


Does this article need to be edited or updated? Please provide feedback.