[Samba] Windows 11 24H2, Samba 4.21.3 AD DC and domain users cannot log in

Virgo Pärna virgo.parna at mail.ee
Fri Jan 24 10:15:27 UTC 2025


On 24.01.2025 11:54, Rowland Penny via samba wrote:
> 
> Which is why I said stop using the old tools, that conversion from 'AD'
> to 'MSK' isn't coming from AD, it is coming from the tools you are
> using.
> 

	It is in samba log file.

> If I were you, I would try resetting the users password, it could be
> something as simple as the PC is using kerberos that is different from
> what the DC expects.
> 

	I have tried reseting user password.
	I also had Windows 11 test-virtual machine, that was not part of 
domain. I added it to domain. And I also added brand new domain account 
with samba-tool. That account works for accesing Windows 10 computers 
and Samba server. But when trying log into Windows 11 Windows says "The 
username or password is incorrect".  So it is not about specific domain 
user.
	And that computer is also Windows 24H2.. I'll need to get myself 23H2 
install media, to test it with that.
	Yet, when logged in with local account,
test-computersecurechannel
shows, that secure channel between local computer and domain is ok... 
But Windows NETLOGON service complains, that it could not set up secure 
session with DC...

-- 
Virgo Pärna
virgo.parna at mail.ee



More information about the samba mailing list