Hi All,
have any of you come accross this issue. when login in to a windows 2000 domain, controled by active directory (server 2000) i get the following msg:

"the system could not log you on to this domain because the systems computer account in its primary domain is missing or the password on that account is incorect"

the password is fine. i have found this somtimes happens when the computer name has been changed, or the computer has be disjioned from the network.

do any of you know how to refresh the account or reset the computer info to restore the account in to its primary domain?

many thanks


check active directory to see if the computer account is still in there but disabled. If it is enable it and you should be fine. If it is gone then you will have to readd the pc to the domain, which will create a new SID. It is best to do this from the pc being added.

Make the machine part of a workgroup... reboot.. then re join it to the domain.

Sounds like your Computer Account is screwed up... If you change PC names without updating it through AD then you are going ot get this error


A little bit of background: your computer uses TWO accounts when logging into a Windows Domain: the Computer account, and the User account.

The Computer account is a behind-the-scenes key with a username (the computer's NETBIOS name) and a password that is made up when the computer first joins the domain. Improper domain management can cause your computer, and the server, to become out of sync concerning this account.

Ways to repair are to go into AD and delete the computer, and then go to the computer, and remove it from the domain. Wait 15 minutes, and then re-join the computer. You have to wait because your domain may be out of sync with the rest of the domain controllers, and you have to wait for a conversation cycle before AD stabilizes.


You can also force replication using ADSI Edit.

But this is only for super impatient admins such as myself :o


I am impressed with your explaination. it is funny how I was thinking all those things but my post didn't come out that way.

You can also check it with replmon, and force it from there. goto support tools directory and run if from there (it part of the kit that comes on the server 2003 server disk)

pls try by resetting the computer account in the AD users and computers , rigth click on the computer account and click reset.

Better than that Wholesale corruptions OF AD no replications and replication failures so Microsoft came in a s sorted it took 10 hours so it weren't a quick fix, The hands free phone went flat in the middle!

Ta anyway

