TL;DR: “The trust relationship between this workstation and the primary domain failed”
The fix only. No explanation, no diagnosis. Read the full article if any of this does not match what you are seeing.
- Sign in with the local administrator account and open PowerShell as administrator.
- First make sure the PC can reach a domain controller (DC) and resolve the domain. If it cannot, fix DNS and the clock before touching the computer password.
nltest /dsgetdc:<domain name>
w32tm /query /status- Confirm the secure channel is really broken.
Test-ComputerSecureChannel -Verbose
nltest /sc_query:<domain name>- Make sure you can get this PC's BitLocker recovery password before changing anything.
manage-bde -protectors -get C:- Repair the channel with a domain account that is allowed to reset computer passwords.
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)- If that does not work, reset the machine password directly, then restart.
Reset-ComputerMachinePassword -Credential (Get-Credential)
Restart-Computer- Check:
Test-ComputerSecureChannelreturns True, then sign in with a domain account.
Do not delete the computer object in Active Directory, and do not rejoin the domain, unless steps 5 and 6 both failed. Deleting the object breaks group memberships and the link to the BitLocker recovery key.
If the DC was restored from an old backup, or replication is broken, the repair has to start on the AD side. Repairing the PC first will not stick.