Friday, May 14, 2010

Workstation Trust Relationship Issue


You receive the following error message, when you try to login to the domain. 

The security database on the server does not have a computer account for this workstation trust relationship. 



1.    Open ADSI Edit
2.    Go to Domain Partition
3.    Right click on the computer and go to Properties.
4.    Double click ServicePrincipalName and verify the SPN value for your Domain
5.    If SPN Value is missing, add a new SPN value in the following format. 

6. Restart the computer. 

Service Principal Name (SPN) - SPN consist of Service Class, Host, Port and Service Name in the following format:

<service class>/<host>:<port>/<service name>

The <service class> and <host> are required. But the <port> and <service name> are optional.

I have seen this issue on Vista, Windows 7, Windows 2008 and Windows 2008 R2 machines. As you might know Winlogon service on these Operating Systems use Kerberos logon. So the Service Principal Names (SPNs) need to be configured properly to support Kerberos Authentication.

However, if you are running Windows 7 or Windows Server 2008 R2, adding the computer to a Windows 2000 domain and running a program that calls the LookupAccountName function to retrieve a security identifier (SID) for an account, you may want to consider the following hotfix:

Other Reference Articles:

Typical Symptoms when secure channel is broken -

Machine Account Password Process -

Kerberos Authentication Problems -


Thank you, it was very helpful.

Thanks for the feedback..

I appreciate your post though this did not resolve my issues with the same "trust relationship.." issue. I see the host/machine_name.domain.local in ADSI edit and another 5 listings that seem to be correct.

I can easily rejoin the machine to the domain though I am trying to figure out why this keeps happening. It is happening more than I would like throughout our Windows 7 network. We deployed using Windows Deployment services and sysprep to create the images. This all goes fine and works. Though throughout the school year, we have machines here and there (not all machines...just a few) that are obviously loosing their connection with AD.

What is confusing is that a machine I am working on now was joined to the domain this past August 2010 and I am just now getting this issue on this machine. Do you have any ideas you could share with me of how to approach this. We are not having replication issues in our AD structure. It seems that the computer password is not changing somehow as I believe it expires after a certain time period. THen the secure channel is broken between it and AD not allowing users to login to the machine.
ANy help would be appreciated.

Do you see any name resolution issues between workstation and DC? Did you verify the SPN?

thanks Santhosh, this was very helpful in troubleshooting quickprep provisioned linked clone desktops with view 4.6. It seems the computer accounts were created without the correct ServicePrincipalName

Thanks for the feedback. You will see this issue if you “cloning” the computer accounts.


I am glad to find this site !

While login in to the client machine (Win7) we are facing the same issue like "The trust relationship failed"
we used to fix this by unjoining the machince from domain and rejoin it. Is there any way to fix this issue without do this stuff.

your answer will must helpful for us.


Hi Venkat,

Did you try the options described in this blog?

Did you verify the SPN?

Great post. Here’s a tutorial that shows how you can easily build an online database-driven web application with a parent-child table relationship, without coding

Огромное спасибо!

This comment has been removed by a blog administrator.

This worked spot on for me! Never even came across ADSI editor before. Thanks a bunch

Thanks santosh.
That was very helpful

I have this problem over a year and I have not find a permanent solution yet. Run Asdi edit on workstation only? or server only or both? Your help is greatly appreciated.

This comment has been removed by a blog administrator.
This comment has been removed by a blog administrator.
This comment has been removed by a blog administrator.

Thanks Santosh.....this helped me a great deal. Is there an explanation on why exactly this happens? For us this happened for a computer that was migrated from a different forest.

Thanks for the feedback. You will see this issue if you “cloning” the computer accounts.

- - - Choi Minzi - - -
look what you made me do lyrics

Hi Venkat, We are facing this issue in our organization for the workstations which have Win7 installed. General solution is to Disjoin, join doamin by using localadmin account. But we are trying to find permanent solution for this problem. I read somewhere, Permanent solution is to upgrade it to Win10. (Note: we are not getting trust relationship issue for the Win10 workstations). I don't think there is issue with SPN in our case. As all the machines are sysprepped after cloning. Any suggestions are welcome! Thanks

Have asked this question to Santosh but any suggestion from anyone is welcome

Hi to all, how is all, I think every one is getting more from this site, and your views are good in favor of new viewers. netflix account

in my case the computer account was disabled, just enable it and the problem was solved.

Thank you!!! Solved my issue!!!

Online religion research paper writing services are very difficult to complete and many students are always searching for Religion Research Paper Services companies to help them complete their custom religion essay writing services.

There are many engineering assignment help writing services and Engineering Writing Services to choose from for those stuck with their engineering research paper writing services and engineering term paper writing services.

It is important to seek psychology research paper help services and psychology case study writing services since students find help when they visit Psychology Assignment Writing Services.

There are many cultural studies paper writing services and Cultural Studies Research Paper Services to choose from for those stuck with their cultural studies coursework writing services and research papers on cultural diversity.

Online psychology essay writing services are very difficult to complete and many students are always searching for Help with Psychology Coursework Writing services to help them complete their psychology research paper writing services and psychology case study writing services.

Architectural science coursework writing help services have become very popular for students studying architectural science assignment writing services as they engage the best online Architectural Science Writing Services.

Thank you so much Edward, but it needs the administrator password and unfortunately I've forgotten my administrator password. Is there any way we can do this without using administrator password? PhD dissertation writing services

Online health & safety essay writing services are very difficult to complete and many students are always searching for Health & Safety Writing Services to help them complete their health & safety research paper writing services and health & safety coursework writing services.

Thanks for sharing it is important for me. I also searched for that from here. Visit our site Epson Printer belgie contacteren

Thanks for sharing such an Amazing information, I Couldn't leave without reading your blog. I have read another good blog, I think you have read it too. click here AVG nummer belgie

Post a Comment

Popular Posts


Twitter Delicious Facebook Digg Stumbleupon Favorites More