Unable to contact Active Directory to access or verify claim types & central policy tab missing

steven h 101 Reputation points
2021-05-21T09:53:35.99+00:00

Dear community,

TL;DR: two problems: Unable to contact Active Directory to access or verify claim types & central policy tab missing. Servers can reach each other when for example I ping them or search for AD users.

I'm setting up an environment with (a.o.) a Domain Controller and File Server and am running into an issue I hope you can help with. I'm trying to use Claim Types to specify access to SMB shares but keep running into the error 'Unable to contact Active Directory to access or verify claim types'. This occurs when I try to set a condition on a folder which is used as an SMB share.

My test setup looks as follows:

  • Domain Controller which is also the DNS server (updated win 2019)
  • File Server (updated win 2019)
  • Both servers are added to a private network and can ping each other over local and public IP.

I've followed the steps as outlined on https://learn.microsoft.com/nl-nl/windows-server/identity/solution-guides/deploy-a-central-access-policy--demonstration-steps-and also consulted https://learn.microsoft.com/nl-nl/windows-server/identity/solution-guides/appendix-b--setting-up-the-test-environment

I've set up a Department Claim type, for now left the resource properties as they are as the departments I needed for now were already present. I created a Central Access Rule and Central Access Policy, applied the CAP through group policy, enabled support for claims, and deployed the policy.

In the advanced security settings > add screen for my SMB share, I can reach the DC without any issues to select a principal, but in the bottom under conditions I'm getting the error 'Unable to contact Active Directory to access or verify claim types'. Oddly enough, in the advanced security settings screen of the folder also the central policy tab is missing.

For good measure I ran gpupdate /force again, rebooted the servers, disabled the firewall on the DC, but still no luck. Does anyone have an idea where I'm going wrong?

ps: tried to add tags that better described this topic, but anything related to smb, file server, dc seemed to not work.

Windows Server Storage
Windows Server Storage
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Storage: The hardware and software system used to retain data for subsequent retrieval.
631 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Yuhan Deng 3,761 Reputation points Microsoft Vendor
    2021-05-24T06:27:01.47+00:00

    Hi,
    Please try these commands first:

    Dcdiag /v >c:\dcdiag1.log
    Repadmin /showrepl >C:\repl.txt
    Repadmin /showreps *

    If any error pops out, please provide us with the screenshots.

    Thanks for your understanding.
    Best regards,
    Danny

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. steven h 101 Reputation points
    2021-05-25T12:53:58.647+00:00

    Hi Danny,

    Thank you for taking your time to help me, I appreciate it very much :)

    I believe you've already pointed me in the right direction: Repadmin /showreps * gives me an LDAP error: LDAP error 81 (Server Down) Win32 Err 58.

    I'm a bit pressed for time today, but I'll investigate this further a.s.a.p. to see if something is wrong with the LDAP server and will post the results back.

    regards,
    Steven


  3. David Sadowski 1 Reputation point
    2022-07-11T12:15:12.63+00:00

    I just noticed the same error on one of my two DCs running Windows 2012 R2 Std servers that share AD and "load balance" DHCP and DNS. We didn't make any changes to both servers recently and only applied Windows updates so one of them must have caused this.
    219561-screenshot-2022-07-11-at-122648.png

    0 comments No comments

  4. Pedro Burgos 0 Reputation points
    2023-12-11T13:30:38.3233333+00:00

    Hello I have the same problem, Someone can help us?.

    Thanks!!

    0 comments No comments

  5. Pedro Burgos 0 Reputation points
    2023-12-11T13:31:32.19+00:00

    Hello I have the same problem, Someone can help us?.

    Thanks!!

    Captura de pantalla 2023-12-11 103823

    0 comments No comments