Created on 06-20-2024 07:52 AM Edited on 10-15-2024 08:14 AM By osmanunal
Description | This article describes a possible workaround for an FSSO authentication issue after Installing the KB5039227 or KB5039217 update. |
Scope | Microsoft Windows Server. |
Solution |
After Installing KB5039227 on Server 2022 or KB5039217 on Server 2019, authentication breaks for end users.
Impact: This impacts deployments set in DC Agent Mode and Polling Mode - Windows Security Event Logs. This impacts FortiAuthenticator deployments set as FSSO Agent.
On Windows Security Event Log polling, a similar log will be found as the one below as a symptom of the failure:
[15680] [I][LSPoller]DoPolling(ip=272D10AC, host=FORTINETLAB/W2k22.fortinetlab.net)-->
On DC Agent Mode, there are no errors or symptoms other than the absence of logon events being sent from DC Agents installed on Windows Server 2019 or 2022 that had received KB5039227 on Server 2022 or KB5039217.
No Impact: This does not impact deployments set in Polling mode: NetAPI or WMI.
Workaround: Possible workarounds are described below:
Uninstall the recently installed update by following the steps in this related KB article: How to uninstall a Windows update.
Note: It is only possible to remove the update if it was installed individually. If the update were part of a CU and Feature Update, removing the update in isolation would not be possible.
If the WSUS server is in use: The WSUS server can install updates on domain computers. Remove the installed and approved updates from the Update Services management console.
After the update is uninstalled, a record of this event will appear in the Windows Update History log.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ Entry name: Auth4
The attached registry file (dcagent_regsitry.reg) can be imported to simplify this step.
This key must be added to the target server under Show Monitored DCs -> Select DC to monitor -> Select Domain Controllers for Monitoring User Logon Event -> DC Agent or Polling mode.
If experiencing the symptoms described above and the workarounds are not working, log a ticket with TAC.
Related documents: Technical Tip: FSSO choose between DC Agent mode or Polling mode https://catalog.update.microsoft.com/Search.aspx?q=KB5039217 https://catalog.update.microsoft.com/Search.aspx?q=KB5039227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.