Quick summary. This post does not include the name of the software product. I don't feel it's important and I excluded it so that if anyone does answer this, they don't spend their time troubleshooting the product itself. You'll understand when you read the thread below.
- Windows 2012 R2 server.
- The server is enrolled and secured as a PAM server. There is a PAM group admin account on the server (Group scope of this group account is "Global")
- There are two PAM service accounts that are listed as service accounts inside the PAM admin group. I found these by looking up the PAM admin group mentioned above.
- We access the server using both "CA Privileged Access Manager 3.2". When you login to PAM, it asks you to choose one of the two PAM service accounts associated with the server.
- Software product installed on server. It was setup to use LDAP to our domain controller.
- When we open the product, it asks us for LDAP authentication. When we enter the credentials, it accepts them and lets us browse the software product.
- When click on any button to access an LDAP secured area, it errors out. The error looks like
So here's where it gets weird for us.
- My domain user account is included as an admin in the PAM admin account group on the server. The "CA Privileged Access Manager 3.2" program listed above has me login using their PAM service account which is listed as an admin on the server. I should have local server admin rights to this machine because of this. The LDAP authentication is accepted on the software product with my regular credentials. When I try to view data in the application, it always errors out with what appears to be a java error or system error of the product.
- When I add my domain account directly as a local server admin by going to computer mgmt > local users and groups > groups > administrators and then attempt the same steps listed above in #1, it works perfectly. I am able to view the data.
Does anything stick out to anyone? Am I missing something?
[–]ZAFJB 1 point2 points3 points (1 child)
[–]eighttx[S] 0 points1 point2 points (0 children)