Hook
Microsoft has a trust problem and over a year in they still haven't fixed it. If your IT team has upgraded to Windows Server 2025 domain controllers, some of your users might be getting locked out of their own computers. Not because they forgot their password, but because Windows quietly broke its own authentication system and nobody at Microsoft seems to be in a hurry to do anything about it as far as I can tell. Every 30 days your work computer does something invisible. It changes its own password with the domain controller. It's a security handshake and it's been doing it for years and it works. Except on Windows Server 2025. It doesn't. The server blocks the update. 30 days pass and the handshake fails. The computer falls off the domain entirely and the user gets a message saying that the trust relationship between their workstation and the domain has failed. I used to work on IT help desk and I used to hate that message. It sounds technical, but what it actually means is that you're not getting in. This is showing up across Windows 10 and Windows 11 machines. It hits harder when every domain controller in your organisation has been upgraded to 2025. IT teams are having to fix machines one by one, offline, running manual commands. In a big organisation, that's hundreds of hours of work and then it breaks again in 30 days. The event logs are throwing curious pre authentication failures. Admins have been raising this on Microsoft's own forums since early last year, and some have given up and rolled their servers back to 2022. Microsoft's response nothing specific to this bug. There's been other Kerberos patches in the meantime for unrelated certificate issues, but the actual trust relationship bug is still open. The thread is still active, the workarounds are still manual. This isn't a niche edge case either. Large enterprises are mostly still on older servers, which is why it hasn't exploded yet. But a server 2025 rollout scale up. This is gonna get much louder. Your IT department needs to know about this before they find out the hard way. If you work in IT and you're planning a server 2025 upgrade, keep at least one older domain controller in the environment, cause that seems to be the one thing that reliably prevents it. Thank you to the two people that messaged me. I'd heard about this, but two people specifically messaged me and said you should talk about this. So thank you Microsoft sort it out.
More breakout videos from this creator.