Reset machine password of a domain controller

ESP IT Guy 31 Reputation points
2021-08-12T22:20:37.797+00:00

Hello,

On my secondary DC I'm seeing the event NETLOGON 3210
This computer could not authenticate with \DC.network.local, a Windows domain controller for domain Network, and therefore this computer might deny logon requests. This inability to authenticate might be caused by another computer on the same network using the same name or the password for this computer account is not recognized. If this message appears again, contact your system administrator.

It doesn't appear to be causing any issues but it's something that I'm sure needs to be addresses. I've seen various articles around the topic but none that are quite the issue I have. The closest I can find is: http://blog.cpolydorou.net/2019/02/domain-controller-machine-password-reset.html

I've never reset the machine password of a DC before so a bit apprehensive to follow along. Thoughts anyone?

Many thanks

Edit: I should also add, this DC runs ADsync and has been happily operating for at least 2 years. I've only recently discovered the event so no idea of when it started. Earliest log was 2 months ago.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,241 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dave Patrick 426.2K Reputation points MVP
    2021-08-12T23:44:46.683+00:00

    Try;
    Test-ComputerSecureChannel
    or
    Test-ComputerSecureChannel -Repair
    or
    The simplest solution may be to move roles off, demote, reboot, promo the problematic one again.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  2. Dave Patrick 426.2K Reputation points MVP
    2021-08-14T14:51:32.387+00:00

    Just checking if there's any progress or updates?

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  3. ESP IT Guy 31 Reputation points
    2021-08-18T20:21:50.697+00:00

    Thanks DSPatrick,

    Sorry I didn't get notified of your replies. I've run the commands you've mentioned and the DC does fail, but the repair doesn't work. I was hoping to avoid demoting as it runs our ADSync. I think the easy answer is the normal windows way of doing a clean install. I'll transfer everything over and bomb the DC in question.

    Appreciate you time. Thanks

    0 comments No comments

  4. Dave Patrick 426.2K Reputation points MVP
    2021-08-18T20:56:18.91+00:00

    Sounds good, you're welcome.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments