Can I use a account which is in Protected Users Group to authenticate in my ldap client through the LDAP/LDAPS protocol ?

雷 严 21 Reputation points
2022-12-19T14:11:09.663+00:00

When I use a account which is in Protected Users Group to authenticate in my ldap client through the LDAP/LDAPS protocol, the windows 2016 server returns the error "Invalid credentials". And the failure reason in the event is "Unknown user name or bad password".
272155-image.png

I want to know that is there any way to make it success ?

Thank you very much.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Limitless Technology 45,151 Reputation points
    2022-12-20T08:33:59.547+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query\issues related to use Protected Users Group to authenticate in ldap.

    Please note that Protected users have some restrictions as listed below. Hence please use non-protected users account in your LDAP query.

    If the domain functional level is Windows Server 2012 R2 , members of the group can no longer:

    Authenticate by using NTLM authentication

    Use Data Encryption Standard (DES) or RC4 cipher suites in Kerberos pre-authentication

    Be delegated by using unconstrained or constrained delegation

    Renew user tickets (TGTs) beyond the initial 4-hour lifetime

    Reference :

    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.