Server 2025 Domain Controllers - Trust relationship issues on workstations after 30 days as "pwdLastSet" value unable to be updated

Anonymous
2025-01-03T12:18:07+00:00

Hi

We have 4 Domain controllers upgraded to server 2025 and about 30+ still on 2022. The newly upgraded servers appear to have a bug where by any workstations going through them are unable to update their "pwdLastSet" value and so after the 30 day limit on that field is hit they then fall into a trust relationship issue with the domain. Is this a known bug of server 2025? Are there any known fixes for this issue?

Windows for business | Windows Server | Directory services | Active Directory

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

54 answers

Sort by: Newest
  1. Anonymous
    2025-01-09T14:09:07+00:00

    I set the maximum machine age policy to 3 days on a test domain with Windows 11 24H2 clients and they all lost their trust relationship and would not authenticate. They also did not update their pwdlastset values in AD.

    Immediately after unlinking the GPO, they were able to authenticate again. Setting to a higher value of 365 days and linking the GPO also allowed them to authenticate.

    Using the reset-computermachinepassword command does change the pwdlastset date.

    I've enabled several logs on the domain controllers and am attempting to decipher which may be of value. The biggest standout is a large number of event 4771 pre-kerberos authentication events from the workstations

    Log Name: Security

    Source: Microsoft-Windows-Security-Auditing

    Date: 1/9/2025 8:04:41 AM

    Event ID: 4771

    Task Category: Kerberos Authentication Service

    Level: Information

    Keywords: Audit Failure

    User: N/A

    Computer: DC.domain.com

    Description:

    Kerberos pre-authentication failed.

    Account Information:

    Security ID:		domain\workstation$
    
    Account Name:		workstation$
    

    Service Information:

    Service Name:		krbtgt/domain.com
    

    Network Information:

    Client Address:		::ffff:10.0.44.102
    
    Client Port:		65463
    

    Additional Information:

    Ticket Options:		0x40810010
    
    Failure Code:		0x18
    
    Pre-Authentication Type:	2
    

    Certificate Information:

    Certificate Issuer Name:		
    
    Certificate Serial Number: 	
    
    Certificate Thumbprint:		
    

    Certificate information is only provided if a certificate was used for pre-authentication.

    Pre-authentication types, ticket options and failure codes are defined in RFC 4120.

    If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-01-09T13:13:57+00:00

    Hello

    I can sign in using domain Admin on this member server.

    And I check the pwdlastset on this member server, it changed as below.

    Yesterday and today.

    Image

    I will check win 11 23h2 tomorrow, and if there is any update, I will update here.

    Best Regards,
    Daisy Zhou

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-01-09T10:55:26+00:00

    Hi Daisy

    Yes that's the issue, the Domain Controllers are fine, the workstations using them are not after 30 days as they fall into a trust relationship issue because they cannot reset their pwdlastset field, or more likely they are resetting the value but only on the workstation while the DC is not updating AD and so they are out of sync.

    Hello

    Good day!

    My test workstation is one member server 2025.

    I can try to find one windows 11 23H2 machine if you need? Please tell me.

    Do you mean "Trust relationship issue" that you can not sign in the windows 11 23H2 machine using any domain accounts (sign in previous and new account that never sign in)?

    Best Regards,
    Daisy Zhou

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-01-09T10:44:15+00:00

    Hello

    Good day!

    My test workstation is one member server 2025.

    I can try to find one windows 11 23H2 machine if you need? Please tell me.

    Do you mean "Trust relationship issue" that you can not sign in the windows 11 23H2 machine using any domain accounts (sign in previous and new account that never sign in)?

    Best Regards,
    Daisy Zhou

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2025-01-08T12:59:15+00:00

    Hi Daisy

    Is the workstation you are testing with windows 11 23H2?

    I have confirmed that a classroom of iMacs that are integrated into our AD have all been able to reset their windows pwdlastset field fine. I have the impression the issue is linked between windows 11 23H2 and server 2025. It could also be other versions but cant confirm totally outside of 23H2 as that's what our end devices are on.

    Was this answer helpful?

    0 comments No comments