Unable to contact Active Directory to access or verify claim types & central policy tab missing

steven h 101 Reputation points
2021-05-21T09:53:35.99+00:00

Dear community,

TL;DR: two problems: Unable to contact Active Directory to access or verify claim types & central policy tab missing. Servers can reach each other when for example I ping them or search for AD users.

I'm setting up an environment with (a.o.) a Domain Controller and File Server and am running into an issue I hope you can help with. I'm trying to use Claim Types to specify access to SMB shares but keep running into the error 'Unable to contact Active Directory to access or verify claim types'. This occurs when I try to set a condition on a folder which is used as an SMB share.

My test setup looks as follows:

  • Domain Controller which is also the DNS server (updated win 2019)
  • File Server (updated win 2019)
  • Both servers are added to a private network and can ping each other over local and public IP.

I've followed the steps as outlined on https://learn.microsoft.com/nl-nl/windows-server/identity/solution-guides/deploy-a-central-access-policy--demonstration-steps-and also consulted https://learn.microsoft.com/nl-nl/windows-server/identity/solution-guides/appendix-b--setting-up-the-test-environment

I've set up a Department Claim type, for now left the resource properties as they are as the departments I needed for now were already present. I created a Central Access Rule and Central Access Policy, applied the CAP through group policy, enabled support for claims, and deployed the policy.

In the advanced security settings > add screen for my SMB share, I can reach the DC without any issues to select a principal, but in the bottom under conditions I'm getting the error 'Unable to contact Active Directory to access or verify claim types'. Oddly enough, in the advanced security settings screen of the folder also the central policy tab is missing.

For good measure I ran gpupdate /force again, rebooted the servers, disabled the firewall on the DC, but still no luck. Does anyone have an idea where I'm going wrong?

ps: tried to add tags that better described this topic, but anything related to smb, file server, dc seemed to not work.

Windows Server Storage
Windows Server Storage
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Storage: The hardware and software system used to retain data for subsequent retrieval.
633 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more