SAP Knowledge Base Article - Preview

1950769 - Some users cannot login to IDT with AD despite having a known good configuration

Symptom

  • Receive error when logging into IDT with Active directory despite having known good configuration files (bsclogin.conf, krb5.ini, and informationdesign.ini)
  • Receive error when logging in with AD "Active Directory Authentication failed to log you on. Please contact your system administrator to make sure you are a member of a valid mapped group and try again. If you are not a member of the default domain, enter your user name as UserName@DNS_DomainName, and then try again. (FWM 00006)"
  • Packet scanning the error you receive "error_code: KRB5KDC_ERR_POLICY (12)" during the AS request / reply
  • AD user can login to BI launchpad, universe designer (UDT) and Webi Rich client fine
  • Ad user account has the option "Smart card is required for interactive logon checked in their account options"


Read more...

Environment

SAP BusinessObjects Business Intelligence Platform 4.0 SP6

Product

SAP BusinessObjects Business Intelligence platform 4.0

Keywords

zie single sign on sign-on silent logon automatic , KBA , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.