JSI Tip 7767. When you attempt to open Active Directory Users and Computers, you receive 'The target principal name is incorrect'?

When you open the Active Directory Users and Computers MMC snap-in on a client computer, you receive:

The target principal name is incorrect.

If you run Dcdiag, you receive:

* Connecting to directory service on server <ServerName>.
\[<ServerName>\] LDAP bind failed with error 31.
A device attached to the system is not functioning.

This behavior is symptomatic of a broken secure channel between the local computer and its domain controller.

To fix the problem:

1. Open a CMD.EXE prompt.

2. Type the following commands, pressing Enter after is one:

nltest /SC_CHANGE_PWD:<DomainName>
netdom reset <ComputerName> /domain:<DomainName>

NOTE: <DomainName> is replaced with the name of your domain, and <ComputerName> is replaced by the name of your local computer.

Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.