TL;DR: Group Policy Event ID 1053 / 1055: “Windows could not resolve the user name” (name resolution failure)
The fix only. No explanation, no diagnosis. Read the full article if any of this does not match what you are seeing.
- Open an elevated Command Prompt or PowerShell on the affected PC.
- Check which DNS servers it is using. They must be servers that can answer for your Active Directory domain, not a home router or public DNS.
ipconfig /all- Prove whether the PC can find a domain controller (DC).
nltest /dsgetdc:<domain name> /force
nslookup -type=SRV _ldap._tcp.dc._msdcs.<domain name>- If DNS is wrong, point the adapter (or the DHCP scope, or the VPN profile) at the AD DNS servers. Then refresh DNS and retry.
ipconfig /flushdns
ipconfig /registerdns
gpupdate /force- If the SRV lookup returns nothing even with the right DNS server, the DC is not registering its records. On the DC, restart Netlogon to re-register them, then test again.
net stop netlogon && net start netlogon
dcdiag /test:dns /v- Check:
gpupdate /forcefinishes without errors andgpresult /rlists the policies you expect.
Do not delete or rebuild GPOs. The policies are almost certainly fine. The PC just cannot find the domain.
Do not add a public DNS server (such as 8.8.8.8) as a "backup" DNS server on a domain-joined PC. Windows will use it, and it cannot answer for your domain.