Issues with domain membership after a system restore (295049)
The information in this article applies to:
- Microsoft Windows XP Professional
This article was previously published under Q295049 SYMPTOMS You may experience the following behaviors:
- If you use System Restore after the password change
interval expired one time, and you restore the computer to a point before the
password changes, the next password change may not occur when it is due.
Instead, the operating system treats the restore as if the password was
changed.
- If you use System Restore after the password change
interval expired two times, and you restore the computer to a point before the
password changes, the domain users accounts on the computer are disabled, and
users receive an error message when they try to log on.
CAUSEWhen you join a computer to a domain, a
computername$ account is created, and a password is
shared between the computer and the domain. By default, this password is
changed every 30 days (MaximumPasswordAge).
The
behavior that is described in the "Symptoms" section occurs because System
Restore only rolls back the local computer state. Part of the information about
joining domains resides in the Active Directory directory service, and System
Restore does not roll back Active Directory.
For the first symptom,
the delayed password change occurs because System Restore rewrites the LSA
secret with the password with the same values. This rewrite updates the time
stamp on the secret that the Netlogon service uses to decide about the password
change time stamp. For the second symptom, there is no locally stored password
that matches the machine account password in Active Directory.RESOLUTION To resolve the first symptom, wait for the computer to
change the password, or force the comoputer to change the password immediately.
To force a password change, run the nltest /sc_change_pwd:domain command. The nltest command is part of the Windows Support Tools. To resolve
the second symptom, use one of the following methods:
- Remove the computer from the domain, and then readd it to
the domain.
- Undo the restoration.
STATUSThis
behavior is by design.
Modification Type: | Major | Last Reviewed: | 3/30/2005 |
---|
Keywords: | kbnetwork kbprb KB295049 kbAudITPRO |
---|
|