Skip to main content
Jalal-ali99
New Member
December 3, 2025
Question

FAC Windows Authentication Fails for Domain-Joined PCs Using MSCHAPv2 (Wrong username or password)

  • December 3, 2025
  • 17 replies
  • 1657 views

Hello everyone,

I'm experiencing an issue with MSCHAPv2 authentication on FortiAuthenticator (FAC) when using Windows AD domain authentication.

My FAC is joined to Active Directory, shows as fully connected to the domain controllers, and I have a RADIUS policy configured with “Windows AD domain authentication” enabled.

Problem Description

When domain-joined Windows PCs attempt 802.1X authentication, they automatically send the logged-in user’s credentials.
However, FAC rejects these attempts with the following log message: "Windows AD user authentication from (null) (mschap) with no token failed: AD auth error: The attempted logon is invalid. This is either due to a bad username or authentication information. (0xc000006d)"

 

interestingly, this issue does not occur on non-domain (workgroup) PCs.
When a user manually enters the same domain username and password, authentication succeeds without any problem.

I have also tested different username formats, including: realm\username and username@realm

But the authentication still fails when the credentials are automatically supplied by domain-joined PCs.

 

Thanks in advance for any help.

17 replies

AEK
SuperUser
SuperUser
December 3, 2025

Hi Jalal

For domain joined PC, are you entering manually the credentials or are they auto-filled?

If auto-filled then try manually and enter them in the exact way as for the non-joined PC.

AEK
Jalal-ali99
New Member
December 4, 2025

Hi 
on domain-joined PCs there is a group policy that forces the PCs to send credential of logged-in users to the authenticator (switch) so there is no need for the users to enter their credential every time after they login.
it's so disturbing to disable this policy for the users and its almost impossible for +300 PCs 

AEK
SuperUser
SuperUser
December 4, 2025

If you can't test with one user then try check in FAC logs the username sent by the client, and compare it with the same for the non-domain-joined clients. Something tells me the difference is here.

AEK
AEK
SuperUser
SuperUser
December 8, 2025

Try this setting in the related RADIUS policy.

 

fac_rad.png

AEK
Jalal-ali99
New Member
December 12, 2025

I have already configured username format in both "username@realm" and "realm\username" but none of them works 

 

AEK
SuperUser
SuperUser
December 13, 2025

Can you share the RADIUS debug logs from both cases?

AEK
sisrayilov
Staff
February 10, 2026
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!