Microsoft confirms Patch Tuesday patch May 2022 causes AD authentication error
After installing the update, Windows admins reported that some policies were faulty. The error message is as follows: "Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing account or the password was incorrect".
This issue affects Windows platforms and systems for clients and servers running all versions of Windows, including the latest available releases (Windows 11 and Windows Server 2022).
Microsoft says this error is only triggered after installing updates on a server used as a domain controller. Updates will have no negative impact when deployed on Windows client and server devices other than Windows Server domain controllers.
"After installing the updates released on 5/10/2022 on your domain controller, you may see authentication errors on the server or client for services like Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP) and Protected Extensible Authentication Protocol (PEAP)", Microsoft shared.
Currently, Microsoft is investigating this issue and will release an update to address it in the near future.
In another support document, Microsoft said it was the patches CVE-2022-26931 and CVE-2022-26923 that caused the AD authentication problem. These are two elevated privilege vulnerabilities in Windows Kerberos and Active Directory Domain Services.
CVE-2022-26923 is a critical vulnerability that allows an attacker to elevate the privileges of a low-level account to an administrator account on default Active Directory configurations.
For the time being, users can work around it by manually mapping the certificate to the machine account in Active Directory.
In the May update, Microsoft also automatically added the Registry key StrongCertificateBindingEnforcement. This key will change the execution mode of the Kerberos Distribution Center (KDC) to Compatibility mode (this will allow all authentication unless the certificate is older than the user).
However, one administrator said that the only way some of their users could log in was to disable StrongCertificateBindingEnforcement by setting its value to 0.
If you don't find this key in Registry Editor, you can manually generate it with the REG_DWORD data type and set it to 0. This will disable the strong certificate mapping check. While this isn't a solution Microsoft recommends, it's the only way people can sign in.
Last November, Microsoft also fixed Windows Server authentication errors related to Kerberos authorization scenarios affecting Domain Controllers (DCs) via emergency updates.
You should read it
- Error 0x80245006 during Windows 7, 8 and 10 update, this is how to fix the problem
- Some Windows 10 machines are locked to update after updating KB5003214 and KB5003690
- How to fix Windows Update error
- 5 most common Windows errors and this is a fix
- Steps to fix error 0x803fa067 when Active Windows
- How to fix a blank screen error after updating Windows 10 April 2018 Update
- How to fix Windows Update error code 0x80240fff in Windows 10
- Windows Update June 2022 continues to cause many annoying bugs
May be interested
- Microsoft begins offering Exchange Server updates in .exe packagescurrently, microsoft has maintained a policy of releasing exchange server security updates (exchange server security updates - su) and hot patches (hotfixes - hf) as windows installer patch files (.msp).
- Apple officially kills iPod Touch and iPod product linein a press release just published, apple officially announced the death of the ipod touch and also put an end to its ipod product line.
- Internet users can now ask Google to remove their personal data from search resultsgoogle has just revised its search engine privacy policy in the direction of promoting user privacy. this includes the addition of an option that allows internet users to request the removal of personal data relating to them from google search results.
- Microsoft officially supports switching accounts without signing out between Microsoft 365 web appsnearly two months ago, microsoft announced that the company was working on a feature that would allow customers to switch between different user accounts easily when using microsoft 365 web apps such as excel, word, powerpoint, onedrive, outlook, etc
- One of the biggest HTTPS DDoS attacks ever seen was stoppedalthough it is not a new form of attack, ddos is always considered the top threat to global organizations and businesses.
- Why Apple's Thunderbolt 4 Pro Cable Is So Expensive, $129thunderbolt 4 pro cable was launched by apple in early march at the same time as mac studio and studio display.