IAM Unable To Join Domain After IWA SSO

|
  • 206
  • 7

Issue Description

IAM unable to join AD Windows Server 2012 R2 after enable IWA SSO,
After submit credential will prompt “Failed to enable Integrated Windows authentication: Failed to be joined to domain! Please submit credentials again or change domain account!”

Handling Process

  • Checked the credential of user account is true.
  • Checked the device able to ping to AD server.
  • telnet AD server with TCP port 100 and it can be access.
  • Checked the account has privilege to access to the domain


Root Cause

During the packet capture, the IAM send RST packet to server due to the smbv1 doesn’t enable inside the windows server.

Solution

  • Run powershell as administrator.
  • Type “Get-SmbServerConfiguration | Select EnableSMB1Protocol, EnableSMB2Protocol” to get the current status of different smb version.
  • Type “Set-SmbServerConfiguration -EnableSMB1Protocol $true” to set the SMBv1 to True.
  • Type “Get-SmbServerConfiguration | Select EnableSMB1Protocol, EnableSMB2Protocol” to make sure it became true as result below.
  • Submit the credential again and it able to join into the domain without any errors.


Muhammad Bilal Lv4Posted 06 Aug 2020 16:26
  
Great  sharing
Faisal Posted 21 Aug 2020 08:07
  
Thank you very much for the information ...
Faisal Posted 23 Oct 2020 08:39
  
Nice article ...
Faisal Posted 17 Dec 2020 08:51
  
Great info ...
Ellechar Lv4Posted 26 Jan 2021 14:50
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 19 Mar 2021 07:17
  
Very informative …
Faisal Posted 04 Jun 2021 12:14
  
Nice guidance ...

I want to write a case
Doc ID: 2308
Author: Sangfor_SY
Updated: 2019-12-23 09:45
Version: