Azure ADDS joined servers keeps getting trust relationship failed with domain

Mohamed Soliman 46 Reputation points
2022-03-25T19:49:28.27+00:00

on-premise servers joining Azure adds domain through site-to-site tunnel keeps getting error message "The trust relationship between this workstation and the primary domain fails"

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,114 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,454 questions
0 comments No comments
{count} votes

Accepted answer
  1. Devaraj G 2,091 Reputation points
    2022-03-26T02:14:45.297+00:00

    Hi Mohamed, thanks for posting.

    There could be multiple reasons (Intermittent connectivity issues to Domain, DNS failures, etc) for trust issues and its common in Directory service infra.

    Azure ADDS primal goal is not intended for on-prem device management or as a direct replacement for Windows AD. Azure AD DS provides a way to move applications that require authentication methods like Kerberos and NTLM, into Azure without extending an on-premises AD directory to Azure.

    Having said that, you can still technically use this for adding on-prem machines to Azure ADDS provided reliable connectivity.

    Are you facing this problem across your on-prem servers/workstations or selected few. ?
    Is the VPN connectivity is stable and verified from firewall end for any port blocks ?

    https://learn.microsoft.com/en-us/azure/active-directory-domain-services/network-considerations


1 additional answer

Sort by: Most helpful
  1. Limitless Technology 39,351 Reputation points
    2022-04-01T14:29:49.157+00:00

    Hi @Mohamed Soliman

    This error indicates that there's an issue with the communication channel between the servers. When an AD domain no longer trusts a computer, chances are it’s because the password the local computer has does not match the password stored in Active Directory.

    Here is a guide to troubleshooting this issue:

    https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/troubleshoot-broken-secure-channel

    I hope this answers your question.

    Thanks.

    --
    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments