Windows 8 Join Domain
Windows 8 either connects to the domain instantly, or else requires numerous adjustments to its network settings.
In this article I will show you how to successfully join a Windows 8 computer to a domain.
Connect Microsoft Windows 8 to a Domain
Let us find the configuration sheet on your Windows 8 machine so that it can join a domain; I began by clicking on the Computer (Icon), then Properties. That took me to the Control Panel System and Security, System. The next step, which you can see on the screen below, is to click on 'Change settings'.
Connecting to the Domain
From the System Properties sheet, Click on 'Change' and set the radio button to 'Domain:' now type the name of YOUR domain in the 'Member of' box. See screenshot below.
In my example I used the name 'BigDom'; if this did not join my Windows 8 machine to the domain, I would have typed the fully qualified domain name, e.g. BigDom.Local Incidentally you could use the same technique to join a Workgroup.
SolarWinds' Orion performance monitor will help you discover what's happening on your network. This utility will also guide you through troubleshooting; the dashboard will indicate whether the root cause is a broken link, faulty equipment or resource overload.
What I like best is the way NPM suggests solutions to network problems. Its also has the ability to monitor the health of individual VMware virtual machines. If you are interested in troubleshooting, and creating network maps, then I recommend that you try NPM now.
Microsoft client operating systems have been joining Windows domains since NT 3.5; each new client employs the above technique, but for each successive operating system Microsoft introduce adjustments to the under-the-covers joining procedure; as a result each Windows clients experienced different connection problems for certain DNS and security configurations.
a) Is this a permissions problem? Make sure you have the domain administrator's password.
Check the Basics
Microsoft's Detailed Troubleshooting Advice
The domain name "BigDom" might be a NetBIOS domain name, which differs from the DNS name. If this is the case, verify that the domain name is properly registered with WINS.
If you are certain that the name is not merely a NetBIOS domain name, then Microsoft supplied this information to help troubleshoot your DNS configuration.
The following error occurred when DNS was queried for the service location (SRV) resource record used to locate an Active Directory Domain Controller (AD DC) for domain "BigDom":
The error was: "DNS name does not exist."
The query was for the SRV record for _ldap._tcp.dc._msdcs.BigDom
Common causes of this error include the following:
- The DNS SRV records required to locate a AD DC for the domain are not registered in DNS. These records are registered with a DNS server automatically when a AD DC is added to a domain. They are updated by the AD DC at set intervals. This computer is configured to use DNS servers with the following IP addresses:
- One or more of the following zones do not include delegation to its child zone:
Note: This information is intended for a network administrator. If you are not your network's administrator, notify the administrator that you received this information, which has been recorded in the file C:\Windows\debug\dcdiag.txt.
Here is an utility where you can review firewall settings such as access control lists (ACL), or troubleshoot problems with network address translation (NAT).
Other reasons to download this SolarWinds Firewall Browser include managing requests to change your firewall settings, testing firewall rules before you go live, and querying settings with the browser's powerful search options.
Guy recommends that you download a copy of the SolarWinds free Firewall Browser.
Full Computer Name - System Icon
My first suggestion is to line-up the client's computer name with the domain name.
Click on 'More..' and append the full dns name to the simple computer name. For example type: Win8.BigDom.local. After the reboot try once again to join the Windows 8 computer to the domain.
Check DNS with Ipconfig
'The following error occurred attempting to
join the domain.
It is vital that the Windows 8 computer can resolve the domain name of the Active Directory that you are trying to join.
Ipconfig /all always reveals interesting information, particularly the DNS configuration.
Follow up by testing with ping:
NSLookup may also help troubleshoot DNS problems.
TCP/IP Adapter Settings
If it already receives an IP Address and a DNS server address via DHCP then this less likely to be the root problem, nevertheless you could manually edit the DNS IP address:
'Use the following DNS server addresses:
Another idea is to specifically set the DNS address to the Windows Server, normally this is one and the same machine, but if DNS has its own server, this may enable you to join Windows 8 to the domain. If you experiment with different values for the IP address you don't need to reboot
Tip 1: Ipconfig /flushdns clears the cache if you are trying to ping different TCP/IP addresses.
Client for Microsoft Networks
I have also heard of problems where a disabled Netlogon service was the root cause of a Windows 8 machine failing to join a domain. Check this and dependent services by launching services.msc.
Tip 2: It's always worth comparing the setting with a second machine, preferably one which has already joined the domain.
Bridged Ethernet for Virtual Machines
Tip 3: When things go wrong, and I eventually find a solution in the logs, I always vow that next time I will start troubleshooting in system Event Log!
NTM will produce a neat diagram of your network topology. But that's just the start; Network Topology Mapper can create an inventory of the hardware and software of your machines and network devices. Other neat features include dynamic update for when you add new devices to your network. I also love the ability to export the diagrams to Microsoft Visio.
Finally, Guy bets that if you test drive the Network Topology Mapper then you will find a device on your network that you had forgotten about, or someone else installed without you realizing!
Download your 14 day free trial of SolarWinds Network Topology Mapper
This is Guy's most contentious advice; almost nobody else recommends this albeit temporary security breach. There are two reason that I disable the firewall when I am troubleshooting; firstly, it has been to know to suddenly enable the Windows 8 computer to join the domain. Secondly, if I don't disable the firewall my brain cannot seem to move on, and it fixates on firewall, when I really want to try another troubleshooting tactic.
I found the firewall settings thus: Control Panel, Windows Firewall. In a more sophisticated domain, you will probably have other firewall settings, however the principle is the same.
Windows Server 2008: Firewall Status - Off
Windows 8 Computer: Firewall Status - On
As a compromise, you could keep the firewall turned on for the public network, and try turning off for the work or private location.
One sign that it was indeed a firewall problem was when I ran the command: ping server. I got a reply from not from plain server, but from server.domain.com. This was an indication that not only were the ICMP (ping) ports open, but also that DNS was correctly configured and resolved my request for server to the fully qualified server.domain.com. As I only got this response after disabling the firewall, my conclusion was firewall was blocking the ports needed for Windows 8 to join the domain.
Even by opening ports, 389, 135, 88 and 53 I still could not join the domain. This is why I took the ruthless approach and just temporarily turned the Windows Firewall Off on the server side.
Rumours and Red Herrings About Joining a Domain
Upgrading from Windows 7
Computer Account in Active Directory
Window 8 either joins the Active Directory domain easily, or else requires a deal of troubleshooting involving DNS name resolution.
In my troubleshooting experiments one way of persuading a Windows 8 machine to join an Active Directory domain was turning off the firewall at the Windows Server 2008 end. In my opinion 'The following error occurred attempting to join the domain' is most likely to be a firewall problem. The other possibility is that the TCP/IP settings for DNS are incorrect. Fortunately it's easy to check the DNS name resolution by using ipconfig and ping.
If you like this page then please share it with your friends
Microsoft Windows 8 Install Related Topics