Hi Daisy,
If you create a new user, can you log into the Windows 11 23H2 machine with the new user credentials?
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi
We have 4 Domain controllers upgraded to server 2025 and about 30+ still on 2022. The newly upgraded servers appear to have a bug where by any workstations going through them are unable to update their "pwdLastSet" value and so after the 30 day limit on that field is hit they then fall into a trust relationship issue with the domain. Is this a known bug of server 2025? Are there any known fixes for this issue?
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Hi Daisy,
If you create a new user, can you log into the Windows 11 23H2 machine with the new user credentials?
Hello
Good day!
I can see the pwdlastset is not changed on one Win 11 Enterprise 23h2 client.
But I can sign in it using domain administrator.
However, if I create a new domain user, I can not sign in the machine with trust relationship fails.
Please feedback this issue via "Feedback Hub" on one client machine (such as Win 11).
Best Regards,
Daisy Zhou
And? What is the fix?:)
Then i will Post my experience here also.
I can say that the Version of Windows 11 is not interesting. Im also in a school and we have win11 22h2,23h2,24h2 clients. Everybody has the Mistake. I think it is not possibile to fix at the moment. Only with gpo for machinepassword.
Im really sure that it has something to do with Kerberos Error ID 7. Everytime when someone is logging in with trust Problems it will show up in event log of the dc.Maybe server patch from tomorrow will fix it?
We will see
Was reading last night and think possibly the Kerberos aspect is an effect of the issue rather than the route cause, as it appears the machine password change process is totally controlled by the local machine and uses Netlogon (RPC) to do it, so am wondering if theres something broken in that, possibly related to the below hardening on server 2025. Just another possibility as I'm going in a bunch of different directions with possible fixes at the moment but as yet nothing appears to rectify it.