Window 11 24H2 / Can't Join Domain

Anonymous
2024-08-28T15:27:07+00:00

We have about 500 PCs on our domain. Functional level is Server 2016. We received our first laptop from Dell which shipped with Windows 11 Pro 24H2 and it will not join. Since it's failure, I've tested various versions of Win10 and Win11 not running 24H2 and they all join just fine.

netsetup.log shows:

08/28/2024 08:09:17:784 -----------------------------------------------------------------

08/28/2024 08:09:17:784 NetpValidateName: checking to see if 'XPS' is valid as type 1 name

08/28/2024 08:09:17:784 NetpCheckNetBiosNameNotInUse for 'XPS' [MACHINE] returned 0x0

08/28/2024 08:09:17:784 NetpValidateName: name 'XPS' is valid for type 1

08/28/2024 08:09:17:810 -----------------------------------------------------------------

08/28/2024 08:09:17:810 NetpValidateName: checking to see if 'xps' is valid as type 5 name

08/28/2024 08:09:17:810 NetpValidateName: name 'xps' is valid for type 5

08/28/2024 08:09:17:816 -----------------------------------------------------------------

08/28/2024 08:09:17:816 NetpValidateName: checking to see if 'domainname' is valid as type 3 name

08/28/2024 08:09:17:816 NetpValidateName: 'domainname' is not a valid NetBIOS domain name: 0x7b

08/28/2024 08:09:28:877 NetpCheckDomainNameIsValid for domainname returned 0x54b, last error is 0x0

08/28/2024 08:09:28:877 NetpCheckDomainNameIsValid [ Exists ] for 'domainname' returned 0x54b

The PC attempting to join sits on the same subnet as our DCs and there are no security appliances/firewalls filtering traffic.

From the 24H2 PC that won't join, I have tried or am able to:

  • perform name resolution to various hostnames via nslookup
  • verified inbound/outbound AD ports are open on our DCs
  • DCs are replicating and are healthy (other PCs join w/o issue)
  • Access any other resource on our LAN
  • Tried statically assigning DNS servers (which are our DCs) on the PCs NIC
  • Disabled Windows firewall on the PC
  • Factory reset the laptop (Dell XPS 13 9345) and attempted again with no success

Another post suggest searching for a registry key relating to NT4Emulator on the DCs in the event the domain ever had an NT4 DC. This key doesn't exist on our DCs and if we had a DC running NT4 here, it was way before my arrival.

I can't think of any reason why this laptop is different other than it's the first running 24H2. I can't seem to find anyone having this issue.

Any help or suggestions is appreciated.

Windows for business | Windows Server | Directory services | Active Directory

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

72 answers

Sort by: Most helpful
  1. Anonymous
    2024-10-24T05:30:59+00:00

    Good Day, we had a similar issue with our domain joined devices. Specifically when upgrading to Win11 24H2.

    What we found was a Encryption policy during GPO assignment was not deploying to devices.

    The policy in question is located under the following location:

    Local Computer Policy - Computer Configuration - Windows Settings - Security Settings - Local Policies - Security Options.

    Policy is called Network Security: Configure Encryption types allowed for Kerberos. And we then enabled the following options to be applied from GPO:

    RC4_HMAC_MD5

    AES128_HMAC_SHA1

    AES256_HMAC_SHA1

    Future encryption types

    Also a good idea to check the following on the client side that is not joining and updating the reg key provided for it to receive the policy.

    Also a good idea to test this policy first before deploying to all devices.

    On the client side

    1. If a policy is specifying a kerberos encryption key then you will need to change the following in the registry
    2. The key will not be present if a policy is not applied
    3. Faulty entry in registry

    Registry Hive: HKEY_LOCAL_MACHINE
    Registry Path: \Sofware\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters\

    Value Name: SupportedEncryptionTypes

    Type: REG_DWORD
    Value: 1, 2, or 3 are a finding.

    1. Registry Hive: HKEY_LOCAL_MACHINE
      Registry Path: \Sofware\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters\

    change to Value Name: SupportedEncryptionTypes       7ffffffc 2. Pc will need to restarted 3. Run a gpupdate /force to enforce the new policies

    Our functional Domain Level is Server 2016

     Hope this info is of assistance
    Regards

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-10-16T16:55:19+00:00

    this needs to be patched quickly. I am currently disconnected from our domain and can only make connection over VPN. this works but is ultra slow. I have been looking for downloading the older windows 11 23H2 (that worked) but can no longer be downloaded to "roll back". this is inflicting serious malfunction for our company, so I would say this is urgent. asking for us to mess around in domain zones and whatever, or registries is something MS cant afford. we are not all geeks and depend on the system to work. please fix SOON

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-11-08T17:42:25+00:00

    any news yet?

    still working around with VPN.

    as if it was possible to still get 23H2 version somewhere, that would help. Then we were able to roll back, even trough reinstall.

    Now we are stuck with 24H2 that has this big issue with domains......

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-10-29T11:19:37+00:00

    I tried this method, changes in gpedit and registry, but not solved. Still my laptop is not connecting with domain.

    Is there any other options.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-10-24T19:33:20+00:00

    some response from MS would be nice! or even better a patch or something. this is not at-home-stuff this is corporate. our daily work is touched by this and is realy holding back our workflow. please escalate!

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments