cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Hurdles with Windows AD Authentication Configuration

former_member211289
Participant
0 Kudos
866

Dear Team,
Please be informed that when we try to configure Windows AD Authentication, we are facing difficulties with various errors.
Kindly check and do the needful.

Process I followed:
Enabled WinAD Authentication
Gave AD Administration name and Default Domain name
Click update
Got Invalid group name, cannot find group (S-1-5-21-3132330154-158638298-2079404797-18577)
Click cancel
Gave SPN and other details
Click update
Got The Active Directory Authentication plugin does require valid global administration credentials in order to access Active Directory. Please specify administration credentials and try again.

Errors:
1. Invalid group name, cannot find group (S-1-5-21-3132330154-158638298-2079404797-18577) ?
We don't have any group named with (S-1-5-21-3132330154-158638298-2079404797-18577), verified in Query Builder.

2. The Active Directory Authentication plugin does require valid global administration credentials in order to access Active Directory. Please specify administration credentials and try again ?

We got to know that AD authentication will not continue if the AD account used to read the AD directory (service account\AD Administration Name) doesn't have read permissions on the Domain Controller.

Thanks
Ram

View Entire Topic
BasicTek
Product and Topic Expert
Product and Topic Expert
0 Kudos

The AD administration account requires read and query rights to AD, furthermore if you are dealing with multiple forests the proper forest trust must be in place.

When your group error occurs with an invalid sid, that would indicate you tried to add a group that no longer exists in AD.

former_member211289
Participant
0 Kudos

Dear Tim,

We haven't tried to add a group that no longer exists in AD.

Below process we followed and getting error.

Process I followed:
Enabled WinAD Authentication
Gave AD Administration name and Default Domain name
Click update
Got Invalid group name, cannot find group (S-1-5-21-3132330154-158638298-2079404797-18577)

Thanks

former_member211289
Participant
0 Kudos

Also, below group doesn't exists in BO system and AD and how can we handle this issue? Is some SI_ID entry exists in CMS DB?

Invalid group name, cannot find group (S-1-5-21-3132330154-158638298-2079404797-18577).