Domain Computers cannot change password

Philip Squires 0 Reputation points
2024-02-15T15:05:02.8333333+00:00

My current job has had an issue with their domain since July 2023, I am new here and in general to IT so you will have to forgive my lack of knowledge.

Essentially, all users have a permanent password only IT can change because if they try, they receive the message "A device attached to the system is not functioning." The event log gives an event id of 7 and reads:

  • "The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client - in realm - could not be validated.
    This error is usually caused by domain trust failures; Contact your system administrator."

There are 2 DC's, DC1 is the PDC but I noticed with nltest that workstations authenticate through the non-primary (DC2) which is a replicated DC of DC1. I'm not sure why that is.
The workstation and DC times match. As far as I can tell, they're talking and there is a secure channel between them. nltest /sc_query is successful, as is all repadmin commands and a ping to/from each DC. I found a few posts about the "device attached to the system is not functioning" part but the solution is ultimately something I can't do, which is completely redo the domain by demoting the old and promoting a new DC. I think that is more of a fix-all instead of an actual solution.

DC1 & DC2 run at a server 2003 level.

Here's some other, possibly unrelated, information: The only error I could find was two GPO's are not in sync and that Sysvol has errors. The sysvol errors pertain to two GPO's that are seldom used if at all.

I'm getting this when running dcdiag on DC1: 

  • "Starting test: FrsEvent
            There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL
            replication problems may cause Group Policy problems."

And I can't run nltest on DC1, it throws ERROR_NO_SUCH_DOMAIN for the exact same command/domain as when I ran it on DC2 which is successful. I don't know enough about AD to know if sc_query can be run on the PDC successfully. To my knowledge, this just happened one day without any intentional changes done by IT. Any guidance would be greatly appreciated. I was told to contact Microsoft support about it on Spiceworks, but can't find proper contact details.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,491 Reputation points Moderator
    2024-02-19T14:00:37.3166667+00:00

    Hi @Philip Squires

    Do you have a trust ?

    Did you check the domain controller health on each domain controller through DCdiag command ?

    Did you try to check and fix sysvol replication ?

    For your information , you should raise Domain and Forest functional level to Windows 2008 R2 or higher and migrate the replication system from FRS ( not supported by microsoft) to DFS-R. Following the error you mentione it on your answer you should reset the secure schannel. For more information please read this article :

    Event ID - 7


    Please don't forget to accept helpful answer

    0 comments No comments

  2. Anonymous
    2024-02-20T06:49:42.9166667+00:00

    Hello Philip Squires,

    Thank you for posting in Q&A forum. There are 2 DC's, DC1 is the PDC but I noticed with nltest that workstations authenticate through the non-primary (DC2) which is a replicated DC of DC1. I'm not sure why that is.
    A: Domain workstations, domain clients or member servers will find any DC in the same site to authenticate. Here's some other, possibly unrelated, information: The only error I could find was two GPO's are not in sync and that Sysvol has errors. The sysvol errors pertain to two GPO's that are seldom used if at all.
    A: You have SYSVOL replication issue, you should try to fix it.
    Before you troubleshoot the SYSVOL replication issue, you need to make sure AD replication status is OK. And I can't run nltest on DC1, it throws ERROR_NO_SUCH_DOMAIN for the exact same command/domain as when I ran it on DC2 which is successful. A: Yes, I can run nltest /sc_query:domain.com on non-PDC successfully and receive ERROR_NO_SUCH_DOMAIN on PDC.

    Here is the result on PDC. User's image

    Here is the result on non-PDC.
    User's image

    I hope the information above is helpful. If you have any questions or concerns, please feel free to let us know. Best Regards, Daisy Zhou

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.