User Tools

Site Tools


networking:windows:active_directory:trust_relationship

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
networking:windows:active_directory:trust_relationship [2015/09/03 11:33]
jcooper created
networking:windows:active_directory:trust_relationship [2018/04/14 12:09] (current)
gcooper
Line 1: Line 1:
-====== Windows Offline Files ======+====== Trust Relationship Failure ======
  
-The Offline Files feature of Windows may be useful for portable computers, but is less useful for desktop workstation PCs.  Why Microsoft enables it by default is beyond me.+Some times when logging into a Windows Domain there will be an error that "The trust relationship between this workstation and the primary domain failed" and no user will be able to log into the domain on that workstation.
  
-Among other problems and annoyances, the Offline Files feature can cause problems where files (such as faxes or scans) don't appear in their designated shared folder in a timely fashion.+The fix is to rejoin the workstation to the domain.  If you break the domain relationship and then rejoin the domain this can necessitate some reconfiguration of the users profiles that have previously logged into the domain.
  
-===== Disable Offline Files Via GPO =====+===== The Fix to avoid profile games=====
  
-http://titlerequired.com/2012/03/22/sbs-2011-essentials-win-7-pro-pack-disable-offline-files/+Not being able to log into the domain can be problematic for just logging into the workstation.  Here are a couple possible solutions.
  
-http://technet.microsoft.com/en-us/library/cc749449%28WS.10%29.aspx (see also first comment)+  * Login as the local administrator .\Administrator the account has to be enabled and you must know the password 
 +  * Unplug the Ethernet cable and use the cached domain credentials This can take a few minutes, be patient I then enabled the local Administrator account and set a password, rebooted and logged in as local Administrator.
  
-http://community.spiceworks.com/topic/128865-how-to-disable-sync-center-offline-files?page=2+==== Rejoin the Domain without breaking relationship ==== 
 + 
 +Use the ''Network ID'' button to re-add the workstation 
 + 
 +**My Computer -> Properties -> Advanced System Settings -> Computer Name (tab) -> Network ID** 
 + 
 +Follow prompts putting in the appropriate credentials and domain.  Reboot and login.
  
-  - Create an "Offline Files" GPO 
-  - Apply the policy to 
-    * Users 
-    * Groups 
-    * OU 
-  - Wait at least 90 minutes (overnight) for the GPO to propagate 
-    * Or force an update 
-      * gpupdate /force 
-  - Reboot the PC 
-  - Test 
-    * gpresult 
  
-==== More Info ==== 
  
-  * Disable Offline Files service (via GPO – disables ‘cscservice’) 
-<file> 
-Computer Configuration\Windows Settings\Security Settings\System Services 
-</file> 
-  * Disable ‘Allow or Disallow use of the Offline Files feature’ setting (via GPO setting) 
-<file> 
-Computer Configuration\Administrative Templates\Network\Offline Files 
-</file> 
-  * Enable Remove 'Make Available Offline' setting (optional) 
-<file> 
-Computer Configuration\Administrative Templates\Network\Offline Files 
-</file> 
-  * Disable CSC Kernel driver (via registry hack or custom ADM – disables ‘csc’) 
-<file> 
-reg add HKLM\SYSTEM\CurrentControlSet\services\CSC /v Start /t REG_DWORD /d 4 
-</file> 
networking/windows/active_directory/trust_relationship.1441301614.txt.gz · Last modified: 2015/09/03 11:33 by jcooper