Event ID 3210 : Trust relationship message

Boopathi S 3,816 Reputation points
2021-05-20T21:25:14.68+00:00

Hi,

New Operating System Deployment completed computers receiving the below message when try to login. Able to login for 3 times successfully with Domain user account. It prompts Trust Relationship message on the 4th restart.

98367-capture.jpg

Please help what is to be checked to fix the issue

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Vicky Wang 2,741 Reputation points
    2021-05-21T09:27:47.057+00:00

    Hi,
    Domain controllers maintain a password-protected channel between each other. When a BDC is brought into a domain, the PDC gives the BDC the current password to use when connecting to the PDC for authentication, account database replication, and other system activities. This password changes automatically on a regular basis. If the BDC is offline when the password changes, or if a BDC is restored from a backup that has an old password, the BDC will not be able to authenticate with the PDC, and Netlogon will fail.
    RESOLUTION :
    In the simplest case, all that has happened is that the domain password has changed. To resolve the behavior, do the following:

    Start the BDC, and open Server Manager
    Select the BDCs name, and select Synchronize with Primary Domain Controller.
    If this procedure is successful, you will get a message that the LSA Database has been updated and Netlogon will start automatically. No other action is necessary.

    However, if synchronizing with the PDC does not work on the first attempt, try carrying out the same command again. Often, a second attempt will succeed. However, if the BDC will not synchronize and Netlogon fails to start after three attempts, you should create a new machine account for the BDC. These instructions are taken from a related article, 137987:

    Using Server Manager, create a new computer name.
    Synchronize entire domain (check another BDCs event viewer to see if it synchronized).
    At the problem BDC, use the Network tool in Control Panel to change the name to the new name


  2. Vicky Wang 2,741 Reputation points
    2021-05-24T06:19:22.423+00:00

    Hi,
    If you find the information I provided useful, you can make my answer
    Thank you for your understanding and support
    Best wishes
    Vicky


  3. Vicky Wang 2,741 Reputation points
    2021-05-26T09:41:41.943+00:00

    Hi,
    Thank you for your reply.
    Looking forward to your update.
    Best wishes
    Vicky

    0 comments No comments

  4. Vicky Wang 2,741 Reputation points
    2021-05-31T08:00:10.427+00:00

    Hi,
    Welcome to share your current situation if there are any updates.
    Please feel free to let us know if you need further assistance.
    Best Regards,
    Vicky


  5. Vicky Wang 2,741 Reputation points
    2021-05-31T09:37:05.067+00:00

    Hi,
    thank you for your reply.
    If the information is useful, can you help me make the answer?
    Thank you for your understanding and support
    Best wishes
    Vicky

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.