I am using deploystudio to enroll images to mac, where I also within a script bind the mac to AD.
It works as it should, and I can logon to any mac with any AD user after enrolling an image
But quite often I see mac´s suddenly are not bind to AD anymore. Typically I find the issue, when user try to change password, and that the login password to the mac can not be changed. It is not all mac users it happens for, but some more then other.
I can see the computer object still are in the AD, so it is not because the computer has been removed from the AD. If I un-bind the AD on the Mac - then delete the computer name in AD - and afterwards bind the mac to AD again it works. Sometimes for months, other time maybe some weeks - it is difficult to say specific, as it is mainly when user change AD password every 3 month, the issue pop up
But what is the best way to troubleshoot, if this is a client issue - or AD for some reason just cut the trust relationship with the mac ?.