Troubleshooting: Invalid User ID or Password Error for a Subset of Users (AD Logon Restrictions)

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    When logging in to SecureAuth Identity Platform, most users authenticate successfully, but a specific subset of users always fail with an Invalid User ID or Password error, even though they are typing the correct password.

     

    Cause

    The affected users' Active Directory (AD) accounts have logon restrictions applied, limiting which machines they are allowed to log on to.

    When SecureAuth Identity Platform validates a user's password, AD counts this as a logon attempt from the IdP server itself (on-premises or hybrid deployments) or from the Connector machine (cloud deployments). If that server is not on the affected user's allowed logon list, AD rejects the logon attempt, which SecureAuth Identity Platform then reports as an invalid password.

     

    Resolution

    Work with your AD administration team to add the SecureAuth server(s) to the allowed logon list for each affected user:

    1. Open Active Directory Users and Computers (ADUC).
    2. Find the affected user and open their properties.
    3. Click the Account tab, then click Log On To
      .The Logon Workstations dialog for a user's Account properties, with 'The following computers' selected and one computer name already listed.
    4. Type in the name of the SecureAuth IdP server or SecureAuth Connector server.
    5. Click Add.
    6. Repeat for each server the user needs to be able to log on to.The same Logon Workstations dialog after adding two more computer names to the allowed list.
    7. Click OK to save the changes.


     

    Special Considerations

    Adding a server to this list only allows AD logon validation to succeed from that server. Users can still be prevented from logging on to these servers directly (for example, over Remote Desktop) by using a Group Policy Object (GPO) or Local Policy to set Deny log on locally.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.