We have recently done a major system overhaul and changed from using Novell
to usin Server 2003 with AD. It has all gone smoothly except for one constant
problem on a small number of machines. We are an educational facility and
becuse of this the computers the students useare protected using protection
cards that return the computers to their previous state at reboot. Even
though changes have been saved to the cards and the computers have been
accepted as part of the AD network every couple of weeks a few of the
computers give a message of not being recognized by the network and the only
way to bypass this is by entering as a local administrator and in properties
of my computer reassigning the computer to the network(that is to say if the
network is called MS it shows in the network tab of the properties as
MS.LOCAL so by deleting it you are requested to enter name and password of
the network administrator)

The computers that are having the problem are all running Win 2000 with one
exception that is a computer running XP. ALL the other computers have no
problems. We are talking about between 5 - 10 computers here where there are
other machines exactly the same make and OS with the same protection cards
that have no problems( Approx 15 machines with Win 2000 and about 80 - 100
with XP) Any ideas?

Re: Changing from Novell to Active Directory by heidenau

heidenau
Sun May 04 01:45:50 PDT 2008

Hello Aryeh,

i think you have the problem with all client computers in your
domain;-). By default all computers change their passwords on the
domain controller every 30 days. When you shutdown the computer the
password is reset to the old one because the protection card resets the
computer to the original state. You have to disable this feature in the
domain security settings.

Default Domain Policy\Computer configuration\Windows Settings\Security
Settings\Local Policies\Security Options

Domain Member: Disable machine account pasword changes


--
Viele Grü�e
Frank Röder
MVP Windows Server System - Directory Services
"Ex oriente lux"


Re: Changing from Novell to Active Directory by Aryeh

Aryeh
Sun May 04 02:01:00 PDT 2008


FIrst of all I thank you for your reply. This however is not the problem.
As I stated ithe problem occurs only with a select number of computers. Other
computers with the same setup do not have this problem and in any case the
password expiry is disabled.