question

Andreas-0221 avatar image
0 Votes"
Andreas-0221 asked Andreas-0221 commented

SCCM - ACTIVE DIRECTORY (SECURITY GROUP/SYSTEM) DISCOVERY AGENT FAILED TO BIND TO CONTAINER

Hello Guys

We have an untrusted domain, where the System and Group discovery worked very well untill the 01-2022 CU patch got installed on the SCCM Site server (Server 2016).

The log is giving me the following error:

Active Directory Security Group Discovery Agent failed to bind to container LDAP://domain.com/OU=ou,OU=ou2,DC=domain,dc=com
Error: The user name or password is incorrect.
Possible cause: The AD container specified earlier might be invalid now. The Domain Controller is inaccessible.
Solution: Please verify that the AD container paths specified are valid. Confirm accessibility of the site server to the Domain Controller to be que**ried.

We use a Service account from the DMZ domain to do the discovery: (dmz\service-account).
If I remove the CU from the Site Server, the discovery works well again.

I hope someone can point me in the right direction with this problem.

/Andy

configuration-manager-general
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Jason-MSFT avatar image
1 Vote"
Jason-MSFT answered Andreas-0221 commented

This is a known issue that I believe we are addressing in 2203.

A workaround that should work is to insert a specific domain controller name in the LDAP path specified in your discovery configuration, e.g., LDAP://dcname/domain.com/OU=ou,OU=ou2,DC=domain,dc=com

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Sorry I almost gave up on this and forgot about this post. Just added the DC name before the domain and it worked.

Thank you very much Jason.

/Andy

0 Votes 0 ·
Amandayou-MSFT avatar image
0 Votes"
Amandayou-MSFT answered

Haven't heard from you for some time, is Jason's answer helpful to you? If it is helpful, please accept answer. It will make someone who has the similar issue easily find the answer.

If you have any other issues, please don't hesitate to let us know.

Thanks and have a nice day.


If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.