When reverting a snapshot on a Microsoft Active Directory domain-joined virtual machine causes service account login failures. The service account fails to sync with the domain controller. This prevents authentication and access to domain resources.
This occurs after performing a snapshot revert operations on Windows virtual machines. The virtual machines must be joined to an Active Directory (AD) domain. The authentication failure prevents access to the virtual machine and may impact business operations.
Error messages may include: "Windows cannot connect to the domain, either because the domain controller is down or otherwise unavailable, or because the computer account was not found."
Other symptoms or descriptions:
"The customer is experiencing a virtual machine issue where login to ESXi fails following a snapshot revert."
Seen in:
The snapshot revert operation restores the virtual machine to a previous state with outdated computer account credentials. The Active Directory domain controller retains the current computer account password. This creates a computer account password mismatch that breaks the trust relationship between the virtual machine and domain controller.
This is expected Microsoft Guest OS behavior after recovering from backup or reverting to a snapshot. To re-establish the trust relationship between the domain-joined device and the Active Directory domain, please contact Microsoft support
For more information about computer account password management in Active Directory environments, see How to disable automatic machine account password changes in the Microsoft Knowledge Base.
For general information about troubleshooting trust relationship issues between workstations and domains, see Broken trust relationship between domain-joined device and its domain in Microsoft Learn.