AD event 5805 and 5723 - computer account not in AD, and we don't know where the physical machine is...


i believe our techs may have ghosted or otherwise reimaged machine, or may have been turned off extended period of time.  cannot find computer in ad users , computers, , tried ldp query for a service principal name, , got nothing.   machine did have entry in dns, deleted, errors still logged on multiple dcs , our pc manager sees machine (assuming via wins) in network neighborhood.  can't delete machine domain through ad users , computers, , can't remove machine domain going local machine because don't know is.  help!!!
also- @ 2003 native functional level- added 2008 dc 6 months ago, if helps...

thanks,
sara

hello,

if machine same sid exists on domain can run trouble, yes. if install 10 computers same image without sysprep machines same.

and yes, ad doesn't take care of computers sid, can join hundreds of machine same sid, ad don't take care about.

but security related tasks , informations create problems, because each machine requesting machine account password, example, every 30 days. lot's of machines exact same sid, started up on different times, give information ad machine account password , results in conflicts.
best regards meinolf weber disclaimer: posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN