This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD-SSO domain join not working

Hi guys,

I tried to connect my Sophos UTM 9 with our DC, so that I can use SSO with standard proxy feature.

Sadly Sophos tells me all the time, that domain join not working. Thats why I searched the discussions and the Knowledgebase and find some tips but nothing worked for me.

Quite odd is that the sophos utm shows up in computers section of dc, but the sso feature is still not working.


I checked system times of both systems (using the same ntp server), time zones, hostname is FQDN, utm is registered in dns and the dns forwarder is set up like described in DNS Best Practice (https://www.sophos.com/de-de/support/knowledgebase/120283.aspx)

We´re using 6 DCs in our domain. Main dc is using W2K12 but there is also a DC using W2K8R2. I saw the Workaround (https://www.sophos.com/de-de/support/knowledgebase/121344.aspx) but its not so easy to reboot he system.


My Questions:

  • Why does the SSO / domain join is not working, although the utm shows up in DC computers?
  • Which dc is used by utm for joining the domain?
  • If the problem is caused by W2k12 and SMB, is there any chance to use the W2K8R2 Server instead (this server is set up under dns request router s in utm)?
  • Any other ideas that I might missed?

Thanks for your support.



This thread was automatically locked due to age.
Parents

  • As mentioned, follow DNS best practice ensuring you can resolve your domain name to the DC server. Also ensure your UTM has a FQDN and is resolvable by the DC server itself. 

  • Since I opened this topic I did some updates and tried it some more times. Sadly nothing of your tips worked for me. DNS settings are as you described in you best practice, the DNS Request Routing server is the Win2k8 Server on which it domain join should work without any problem.

    Searching my logfiles I found an entry in "configuration deamon" which is as follow: "Failed to join domain: failed to set machine spn: Operations error"

    All solution I found was about DNS settings, and I´m quite sure they are ok.

    Any ideas?

  • I had this issue.

    The only way I could get it to work was to set my DNS forwarders on the UTM to my local DNS server.

    Then the UTM joined the Domain with no issues.

Reply Children