Server 2025 Domain Controllers - Trust relationship issues on workstations after 30 days as "pwdLastSet" value unable to be updated

Anonymous
2025-01-03T12:18:07+00:00

Hi

We have 4 Domain controllers upgraded to server 2025 and about 30+ still on 2022. The newly upgraded servers appear to have a bug where by any workstations going through them are unable to update their "pwdLastSet" value and so after the 30 day limit on that field is hit they then fall into a trust relationship issue with the domain. Is this a known bug of server 2025? Are there any known fixes for this issue?

Windows for business | Windows Server | Directory services | Active Directory

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

54 answers

Sort by: Most helpful
  1. Anonymous
    2025-02-13T13:36:37+00:00

    We had a laptop with a domain trust issue, and we managed to resolve it. We upgraded the laptop to version 24H2 and performed a force renew using the following command:

    Reset-ComputerMachinePassword -Server "Server-dc" -Credential domain\"admin account"
    

    After running this command, we were able to log in to the domain without any issues. To prevent further problems, we have disabled the machine account password change through a GPO.

    Moving forward, we have two options: either Microsoft will address the issue, or we will upgrade all workstations to version 24H2, as we have already started the upgrade process.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-01-15T14:11:52+00:00

    The same behaviour continues on our environment where on my 2 test machines 23H2 breaks every 24/48 hours but 24H2 continues to work. My colleagues Test environment also behaves in the same way where 23H2 breaks but 24H2 (upgraded from 23H2) and 24H2 direct builds work correctly. Also within our production environment i have seen Windows 10 and iMacs embedded into windows continue to work as expected so I'm fairly confident its a 23H2 bug. I cant be 100% sure that there aren't other bugs that then also effect other operating systems but to me 23H2 is the most affected in our instance.

    Unfortunately the sites where I moved our DC's onto 2025 were primarily 23H2 because i had been delaying 24H2 due to all the bugs that Microsoft were fixing which is ironic (though from what i have read of the bugs i don't think they will effect us greatly). I am moving all of our 23H2 clients up to 24H2 now as i think this is likely to help at the very least as 24H2 and 2025 are based upon the same underlying operating system build.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-01-15T08:56:21+00:00

    Hi Daisy

    I'm sorry but are you telling me i have to use the consumer "Feedback Hub" to report this rather than you escalating it to the engineers to rectify with all the information from this thread?

    We have done most of the legwork to find what is a very big issue and it sounds like you then also want us to then use a non escalated route to get it to the programmers at Microsoft who will need to rectify it? If so that's beyond ridiculous, you need to be escalating it at this point not us.

    Best regards

    Erin

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2025-01-10T12:57:03+00:00

    So my colleague setup a clean infrastructure, process was as below and shows this is a legitimate issue with something on one of the operating systems.

    1. Install Server 2019, upgrade to server 2022, upgrade to server 2025 (this follows the setup for most of our DC's though we have seen same behaviour at 1 of our sites that was freshly built to 2025 due to a hardware failure)
    2. Install 2 workstations with windows 11 23H2
    3. Set machine account password max age for the machines to 1 day.
    4. NO GPO's added or amended, only the default domain controller and domain policy are in place + the 1 setting to amend machine password max age.

    First workstation has just trust relationshipped itself into oblivion. We expect the second one to do so shortly as it passes the 1 day mark.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2025-01-06T08:59:08+00:00

    Hello

    Greetings!

    Are there no current bugs etc linked to server 2025 domain controllers that relate to this issue?

    A: I suggest you can try to set up only one 2025 Windows server Domain Controller in one single domain in one forest. Then check if there is such problem.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments