windows 7 image and AD trust relationship

Discussions about using Windows guests in VirtualBox.
Post Reply
derrellsimpson
Posts: 4
Joined: 4. Jun 2015, 19:05

windows 7 image and AD trust relationship

Post by derrellsimpson »

I have a windows 7 domain joined VM that i use on multiple macs. I use the same VM file and copy and load it into each computers virtualbox inventory. Problem is that randomly, and usually ALWAYS after a password change, two if not all (there are three instances in total) lost their trust relationship with AD. I'm sure AD is seeing some anomaly because the same image is being connected from different machines. Is there some setting that i need to adjust to make the image indistinguishable from virtualbox instance to virtualbox instance?

thank you all in advance!

DS
noteirak
Site Moderator
Posts: 5231
Joined: 13. Jan 2012, 11:14
Primary OS: Debian other
VBox Version: OSE Debian
Guest OSses: Debian, Win 2k8, Win 7
Contact:

Re: windows 7 image and AD trust relationship

Post by noteirak »

Your issue is because the Windows 7 image keeps a SID to uniquely identify the computer in the domain and use that token to talk to the AD DC. If two machines have the same SID, they'll loose trust relationship (since that SID is no longuer valid as a unique identifier).
This is related to AD and Windows, not to VirtualBox in any way.

If you want to be able to copy a VM around, you'll need to do it BEFORE joining the domain and modifying the computer name in the guest BEFORE joining as well.
Hyperbox - Virtual Infrastructure Manager - https://apps.kamax.lu/hyperbox/
Manage your VirtualBox infrastructure the free way!
derrellsimpson
Posts: 4
Joined: 4. Jun 2015, 19:05

Re: windows 7 image and AD trust relationship

Post by derrellsimpson »

if the VM image is identical, How does the win7 machine identify itself differently? is there a unique setting in virtualbox that i can make sure matches between all virtualbox installs so that AD will not see the VMs as different? they are never on at the same time.

thanks,

DS
Martin
Volunteer
Posts: 2562
Joined: 30. May 2007, 18:05
Primary OS: Fedora other
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: XP, Win7, Win10, Linux, OS/2

Re: windows 7 image and AD trust relationship

Post by Martin »

That has nothing to do with VirtualBox.
You cannot have multiple "identical" systems connected to AD at different times, because each client communicates to the domain controller to create dynamic internal keys and passwords for the client system account.
As soon as one of the clients has done this all other clients are out of sync and don't have the correct keys anymore.
noteirak
Site Moderator
Posts: 5231
Joined: 13. Jan 2012, 11:14
Primary OS: Debian other
VBox Version: OSE Debian
Guest OSses: Debian, Win 2k8, Win 7
Contact:

Re: windows 7 image and AD trust relationship

Post by noteirak »

noteirak wrote:This is related to AD and Windows, not to VirtualBox in any way.
Hyperbox - Virtual Infrastructure Manager - https://apps.kamax.lu/hyperbox/
Manage your VirtualBox infrastructure the free way!
Post Reply