How can I check if my Windows 10 or 11 PC is properly joined to a Domain Controller?


Frank15

Member
Local time
9:12 AM
Posts
21
OS
Windows 11 Home
I noticed that,

1. Even if my Windows Sever 2019 domain controller is turned off, I can log into the domain, and the whoami command shows: domainName/computerName


2. Even if I’m logged in with a local account, the advanced System Properties applet shows that I’m logged into a domain (I wonder why):
1714506906704.png

How can I check that I’m logged in and properly connected to a domain controller?

Any insights much appreciated
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte B550M DS3H
the advanced System Properties applet shows that I’m logged into a domain
This isnt what its showing. It is saying your machine is joined to a domain, has nothing to do with the user logged in status.

A local account can be logged into the domain as long as that user is in AD. So can a microsoft account.

Don't confuse the local and microsoft accounts from an AD account.

It really depends if you are using active directory or azure.
Even if my Windows Server 2019 domain controller is turned off,
That is because the account is cached. When a pc cannot see the domain, it will let you log in with the last password and account info that was cached on the machine. If you were to delete that account from the pc and try to sign in with the account on the pc with the domain controller unavailable it will fail.

How can I check that I’m logged in and properly connected to a domain controller?
At the logon screen, it will by default log into the domain once joined. You can see this by clicking on other user in the bottom left at the logon screen, and see it will say sign into: yourdomainnamehere for example. If you wanted to sign into the computer only, you can see an example by clicking on how do I sign into another domain? And you will see the text showing how to type in your computer name \local user name to sign in the machine without the domain. But again, you can only do this with a cached profile.

Also if the account is not logged into the domain, you will not be able to access network resources, such as mapped network drives or printers.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    2TB XPG nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Internet Speed
    900mbps DOWN, 100mbps UP
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
This isnt what its showing. It is saying your machine is joined to a domain, has nothing to do with the user logged in status.

A local account can be logged into the domain as long as that user is in AD. So can a microsoft account.

Don't confuse the local and microsoft accounts from an AD account.

It really depends if you are using active directory or azure.

That is because the account is cached. When a pc cannot see the domain, it will let you log in with the last password and account info that was cached on the machine. If you were to delete that account from the pc and try to sign in with the account on the pc with the domain controller unavailable it will fail.


At the logon screen, it will by default log into the domain once joined. You can see this by clicking on other user in the bottom left at the logon screen, and see it will say sign into: yourdomainnamehere for example. If you wanted to sign into the computer only, you can see an example by clicking on how do I sign into another domain? And you will see the text showing how to type in your computer name \local user name to sign in the machine without the domain. But again, you can only do this with a cached profile.

Also if the account is not logged into the domain, you will not be able to access network resources, such as mapped network drives or printers.
Thanks a lot for the insights. But, how can I know that I'm properly connected to the domain controller? I mean: if the domain controller is offline or the dns settings on the Windows 10 client aren't pointing to the right name server for the domain, I can still log in like you said. Is there any command, or anything I can check in the graphical user interface, to make sure that I’m properly logged in and connected to the DC?
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte B550M DS3H
If you can ping the controller its likely you are authenticating when you sign in, if you cannot you are using cached creds
 

My Computer

System One

  • OS
    PE
It seems like I found a way:

To know that I'm properly connected and logged into a domain controller: use these two commands
- whoami: it should return domainname\username
- gpupdate /force: if it completes successfully, you know you're properly joined and logged in to the domain controller
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte B550M DS3H
Thanks a lot for the insights. But, how can I know that I'm properly connected to the domain controller? I mean: if the domain controller is offline or the dns settings on the Windows 10 client aren't pointing to the right name server for the domain, I can still log in like you said. Is there any command, or anything I can check in the graphical user interface, to make sure that I’m properly logged in and connected to the DC?
The easiest way to know is if you have access to network resources, you're on the domain. If you do not, then you aren't.

However, there is this:


It seems like I found a way:
To know that I'm properly connected and logged into a domain controller: use these two commands
- whoami: it should show domainname\username
- gpupdate /force: if it completes successfully, you know you're properly joined and logged in to the domain controller
gp update force. haha that is a clever way. Didn't consider that. However, gpupdate force can fail even if your connected to the domain properly. For example, if there is an issue in the record for group policy. It isn't super common for that to happen but it is possible.

As for the who am I, if I disconnect the ethernet and I am not connected, it will still show the domain listed there
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    2TB XPG nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Internet Speed
    900mbps DOWN, 100mbps UP
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
The easiest way to know is if you have access to network resources, you're on the domain. If you do not, then you aren't.

However, there is this:



gp update force. haha that is a clever way. Didn't consider that. However, gpupdate force can fail even if your connected to the domain properly. For example, if there is an issue in the record for group policy. It isn't super common for that to happen but it is possible.

As for the who am I, if I disconnect the ethernet and I am not connected, it will still show the domain listed there
Thanks for the answer. This one seems to be good:

Test-ComputerSecureChannel -Server rts-dc1.rtsnetworking.com

And not:
Test-ComputerSecureChannel #this one gave TRUE even if the DC was disconnected
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte B550M DS3H

Latest Support Threads

Latest Tutorials

Back
Top Bottom