Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jalal-ali99
New Contributor

FAC Windows Authentication Fails for Domain-Joined PCs Using MSCHAPv2 (Wrong username or password)

Hello everyone,

I'm experiencing an issue with MSCHAPv2 authentication on FortiAuthenticator (FAC) when using Windows AD domain authentication.

My FAC is joined to Active Directory, shows as fully connected to the domain controllers, and I have a RADIUS policy configured with “Windows AD domain authentication” enabled.

Problem Description

When domain-joined Windows PCs attempt 802.1X authentication, they automatically send the logged-in user’s credentials.
However, FAC rejects these attempts with the following log message: "Windows AD user authentication from (null) (mschap) with no token failed: AD auth error: The attempted logon is invalid. This is either due to a bad username or authentication information. (0xc000006d)"

 

interestingly, this issue does not occur on non-domain (workgroup) PCs.
When a user manually enters the same domain username and password, authentication succeeds without any problem.

I have also tested different username formats, including: realm\username and username@realm

But the authentication still fails when the credentials are automatically supplied by domain-joined PCs.

 

Thanks in advance for any help.

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Jalal

For domain joined PC, are you entering manually the credentials or are they auto-filled?

If auto-filled then try manually and enter them in the exact way as for the non-joined PC.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors