Computer accounts have passwords like user accounts, even if you never interact with them. In an AD domain, computer passwords are used to establish the secure channel to the domain. By default, the computer account passwords do not expire. But a computer renews its password every 30 days by default (more details).
In your case, you took a snapshot of a VM. After that, this machine changed its password at some point (< 30 days). After reverting back to the snapshot, your machine used its old password again, which does not match the password inside your AD.
In conclusion, your machine is not longer connected to the domain and does not have any trust to recreate the secure channel. So you cannot use anything on your machine to rebuild it (like the computer account or any other account from the domain). You have to regain the trust by a new authentication.
I do not recommend to hard code any credentials anywhere, especially not the credentials of a domain admin. You can even reverse the password from a C# (or any) binary. It is only a matter of effort (not necessarily time!).
The only solution, I can think of, is to enlarge the period for computer account password renewal. If you can determine a reasonable timespan, where you can tell that a snapshot will for sure not be older than this, you can modify the renewal interval via GPO (more details):
- Go to
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options.
- There you can activate the setting
Domain member: Maximum machine account password age and set it to a value between 1 and 999 days.
It has to be applied to a location that contains the computer accounts of your VMs. It does not necessarily have to be applied to your DCs, as the computers are changing their passwords themselves. The change is not initiated by your domain (controllers).
Security consideration: The larger the interval, the more time for a brute force attack. Choose wisely.