Sign in problem on Domain after updates

Topweasel

Diamond Member
Oct 19, 2000
5,437
1,659
136
So this year my domain at work has been having issues and it seems to be growing or at least they are getting frustrated enough with it that they have started to bring it to my attention more and more often.

As my machine has this issue as well I will give you what I have experienced. This a Windows 7 computer running WSUS updates that are pruned by our parent company. Since January or February I have had problems where I go to sign into my computer it will tell me my password is incorrect. Eventually I would restart my computer in frustration and it would work. As a few other people brought similar issues to my attention we found that even just unplugging from the network and plugging back in would take care of it. This was a little annoying but a restart to start the day once every couple of weeks isn't the end of the world.

Now fast forward to April and I realize new OS installations are having a similar issue during our Desktop management softwares attempts to set it up. It gets me thinking and I start paying a lot more attention to when my PC displays the issue. I found that it happens only after windows updates are ran, the very next boot, if it is connected to the network, it will have this issue. It doesn't happen every update cycle but it only happens after updates.

Now once I realized this I got in touch with IT at our parent company's office and they tell me that they have seen the same thing and have had a ticket open with Microsoft for some time on this issue. Which is fine and dandy but user frustration is growing with this issue and was major complaint from some Managers to my Manager. Problem is my Google Fu is really failing me everything I see for login issues is single machine or user related and perpetual usually require new profile being generated, system restore, or system reload.

Has anyone else seen a problem like this before?
 

XavierMace

Diamond Member
Apr 20, 2013
4,307
450
126
What does the event log on the nearest DC show when a computer is failing to log in? What does the event log on that computer show after you get logged in? What software are you using for desktop management? Has a password complexity GPO been changed?
 

Topweasel

Diamond Member
Oct 19, 2000
5,437
1,659
136
What does the event log on the nearest DC show when a computer is failing to log in? What does the event log on that computer show after you get logged in? What software are you using for desktop management? Has a password complexity GPO been changed?

Nothing on the event logs but we did a domain transfer to our parent companies domain last year and have limited access to our local domains controllers.

The computer doesn't show anything in the logs. It's like it's not even trying. You see the booting activity, if I restart it I see that, and then you see the attempts that actually went out to the DC.

Heat's DSM.

Yes but only when we did the domain transfer 1 year and 2 months ago. The machine I am using has been freshly wiped and reinstalled since both happened. Also our parent company has been seeing this as well and they have had this rule in place for 4+ years.
 

Topweasel

Diamond Member
Oct 19, 2000
5,437
1,659
136
What version(s) of Windows Server are your domain controllers running?

https://blogs.technet.microsoft.com...server-2012-r2-domain-controllers/#pi168909=7

Ours is are 2012. I don't have the server list for our parent company. They applied a lot of pressure on us to remove or isolate and 2003 or XP machines. But it is possible and I can pass this by them.

I didn't see the Kerberos error specified in that but maybe I wasn't looking carefully enough (everything we hear is well after the fact so I barely ever get to see the problem on a user computer). I will look more carefully at mine, and maybe tomorrow do a reinstall to a loaner pc and let it do the updates.

But the other part of that problem is that it requires a recent password change. None of that is happening. On the newly installed machines it installs 100+ updates and I restart and passwords never used on the system that are 2+ months old are not working.