Share via


Exchange Event ID 1030, 4625 and Outlook Anywhere fail

My friend asked me, why has Exchange every few minutes EventID: 1030, Source: MSExchangeTransport!!

Event ID: 1030
Source: MSExchangeTransport
Task Category: SmtpReceiveSMTP completed authentication but could not determine the account name or security identifier (SID) for the following reason: The trust relationship between this workstation and the primary domain failed.

Here is MS link about this:

Event ID 1030

Exchange work fine, no any errors or warning with Domain Controller!!!
Domain controller work fine, no any error or warning in event viewer!!!
We can using RDP from Exchange to DC or other servers or from outside (Internet to LAN), Exchange can send and recieve mails to/from outside, Users can using OWA, admin can logon to ECP web page and etc.!!!!
But, users can not using Outlook Anywhere!!! When users using Outlook Anywhere, Exchange security log shows Event ID 4625!!

An account failed to log on.

Subject:
   Security ID:  NULL SID
   Account Name:  -
   Account Domain:  -
   Logon ID:  0x0
Logon Type:  3
Account For Which Logon Failed:
   Security ID:  NULL SID
   Account Name:  administrator
   Account Domain: 
Failure Information:
   Failure Reason:  Unknown user name or bad password.
   Status:   0xc000006d
   Sub Status:  0xc0000064

But secure channel work fine between DC and Exchange!!!
What really happened ??
That was security identifiers (SIDs) problem. Your problem do not resolve with rejoin Exchange to domain.
Now Story: my friend used a VM template, without runing Sysprep!!!
After installing a clean Windows server for Exchange and installed Exchange, Event ID 1030 stopped and users used Outlook Anywhere without any problem (keep in mind: you must demote old Exchange correctly).
I hope useful for other people, who did not run Sysprep on VM template. If you need to know, how to create a VM template, please read this link:

About Virtual Machine Templates