Credentials popup while clicking on check names while granting permissions on Folder

Vikshit Jain 1 Reputation point
2022-04-05T12:48:25.573+00:00

We have a service account, which when we use to login to server and try to grant permissions to the folder and try to enumerate users in AD by clicking on check names, it gives us credentials prompt. Even if we provide credential for this account it does not allow us to enumerate the users.

190165-image.png

If we use a personal account we do not see this prompt and it works fine. We are not able to identify what permissions are required so that this account is able to enumerate users from AD.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,124 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,852 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
    2022-04-05T17:57:15.827+00:00

    By default, all users can enumerate accounts in AD. There are no specific permissions to grant (unless there was some heavy customization done by the AD admins).

    In your case, the issue might not be with the permissions of your account on AD, but the privilege your account has on the local system.
    Could you open the security event log of the machine on whch you are trying and see if you find event 4625 indicating a failed logon for that account? Even if you have typed the right password, an failed logon event 4625 will be logged if that's in fact a privilege issue on the machine (well of course if the right auditing is in place, but let's see).

    There are other potential factors (such as trust configuration, and domain controller security settings), but let's check the obvious first.


  2. Limitless Technology 39,351 Reputation points
    2022-04-06T08:39:33.283+00:00

    Hi @Vikshit Jain

    This can happen If your SERVICE ACCOUNT that you are using is not recognized to the domain that you are trying to validated from.

    Plse check if you are facing issue with other Domain accounts as well ?

    --

    --If the reply was helpful, please don’t forget to upvote or accept as answer. --