Users may see the following error while attempting to log in with a domain account:
This happens even when the domain is properly connected and user passwords are valid. However, logging in with the local ADManager Plus admin account works without issues.
Invalid service account password: The service account password configured for the domain might be incorrect or expired.
Duplicate NetBIOS names: Multiple domains may share the same NetBIOS name, causing conflicts.
Incorrect SAML mapping: SAML attribute mapping may be misconfigured or return multiple users.
Domain connectivity issues: ADManager Plus may be unable to reach the domain controller due to network issues.
Have admin access to ADManager Plus and the domain controller.
Log in to ADManager Plus as an admin.
Navigate to Directory/Application Settings > Active Directory.
Make sure the domain connection status shows as Success.
Ensure the configured service account password is correct.
Update the password in ADManager Plus if it has been changed recently.
Check if multiple domains have the same NetBIOS name under Directory/ Application Settings.
Navigate to Delegation > Configuration > Logon Settings > Single Sign-On.
Verify the Mapping Attribute under your SAML configuration.
Use the AD Search option in ADManager Plus to confirm that the mapping value (e.g., mail) returns only one user.
If multiple users are returned, update the attribute or resolve duplicates in Active Directory.
Periodically update and reconfigure the service account password in ADManager Plus.
Regularly review and test authentication settings to avoid login issues.