And? What is the fix?:)
Server 2025 Domain Controllers - Trust relationship issues on workstations after 30 days as "pwdLastSet" value unable to be updated
Hi
We have 4 Domain controllers upgraded to server 2025 and about 30+ still on 2022. The newly upgraded servers appear to have a bug where by any workstations going through them are unable to update their "pwdLastSet" value and so after the 30 day limit on that field is hit they then fall into a trust relationship issue with the domain. Is this a known bug of server 2025? Are there any known fixes for this issue?
Windows for business | Windows Server | Directory services | Active Directory
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
54 answers
Sort by: Oldest
-
Anonymous
2025-01-13T17:12:15+00:00 -
Anonymous
2025-01-14T09:15:31+00:00 Hello
Good day!
I can see the pwdlastset is not changed on one Win 11 Enterprise 23h2 client.
But I can sign in it using domain administrator.
However, if I create a new domain user, I can not sign in the machine with trust relationship fails.
Please feedback this issue via "Feedback Hub" on one client machine (such as Win 11).
Best Regards,
Daisy Zhou
-
Anonymous
2025-01-14T09:22:59+00:00 Hi Daisy,
If you create a new user, can you log into the Windows 11 23H2 machine with the new user credentials?
-
Anonymous
2025-01-14T09:50:15+00:00 Thanks good that a microsoft employees can confirm the issue. I pray for a fix^^
Maybe the clients are finding domain to late at start up? And cant send the password change to server?
-
Anonymous
2025-01-15T08:56:21+00:00 Hi Daisy
I'm sorry but are you telling me i have to use the consumer "Feedback Hub" to report this rather than you escalating it to the engineers to rectify with all the information from this thread?
We have done most of the legwork to find what is a very big issue and it sounds like you then also want us to then use a non escalated route to get it to the programmers at Microsoft who will need to rectify it? If so that's beyond ridiculous, you need to be escalating it at this point not us.
Best regards
Erin