AD Authentication - Does it even work?
I have deployed ServiceDesk Plus (Version 9.1, Build 9112) on a Windows 2008 R2 server. The domain controllers are Windows 2012R2. The domain level is 2008R2.
I have followed the instructions numerous times for AD authentication and pass-through authentication only to have the following issues happen -
- AD authentication without pass-through authentication disabled = FAILS.
- The user is told "Username or Password is incorrect"
- AD authentication with pass-through authentication enabled = FAILS.
- My domain administrator account, which is also my working, day to day, account, and is also an admin in ServiceDesk plus can automatically pass through. However, a normal user account is prompted with a Windows credentials logon window when the navigate to the web page of ServiceDesk plus. If they enter their network credentials the Windows credentials logon screen closes and they now have to enter their user ID info at the ServiceDesk plus website - it does not pass through. If they enter their credentials on the ServiceDesk plus web scree they are told that the "Username or Password is incorrect".
I have deleted all settings for AD authentication and reapplied it only to end in the same situation in most cases.
However this last attempt to correct the issue has resulted in the following:
- When I enable pass-through authentication from the actual server that is running ServiceDesk Plus, while logged in with the built in administrator account, I am presented with a Windows credentials dialog box. I kind of expect this I guess as the account I am using is not a domain account in any way. If I login with my domain admin account, which again is also a ServiceDesk plus admin account, and enable or disable pass-through authentication, I am not presented with a Windows credentials dialog box. In previous attempts to enable/disable pass-through authentication and setup all AD connectivity, I was always logged in with the built in administrator account and was never prompted for Windows credentials.
- Unfortunately, once pass-through authentication is enabled, the result is the same as my previous attempts. My domain/ServiceDesk plus admin account passes through without an issue but any normal user account is prompted for Windows credentials before they can enter anything via the ServiceDesk plus website, and then once they attempt login to ServiceDesk plus they are told the "Username or Password is incorrect".
So.. I have to ask:
- Does AD Authentication and Pass-through authentication even work?
- Does it work with a Windows 2012R2 domain?
- Is it reliable? There are some threads here that it will be working one day and then stop the next. I do not need this in my environment.
New to ADSelfService Plus?