This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Upgraded AD Controllers to Windows 2016 RTM and UTM 9.407-3 AD Single Sign-on Stops working

Today we upgraded both of our Windows 2012 R2 Domain Controllers to Windows 2016 Server (RTM Release) with all updates applied through today. Single Sign-on in UTM 9.407-3 which was previously working fine with the 2012 R2 Domain Controllers stopped working and all users began getting prompts for username/password in all web browsers. We have seen this before and went to Definitions & Users -> Authentication Services -> Single Sign-On and removed UTM from the domain, restarted UTM and then attempted to re-join it to the domain. The rejoin failed and we have tried the following: Using Domain Administrator account for join, Making sure NTLM is enabled on the domain, Making sure SMB1 is installed (did a remove and re-install as some article had suggested), removing the UTM machine account from AD Users and Computers. After trying everything we could think of and 50+ domain joins failing, we reverted the domain controllers back to 2012 R2 and domain join began working again right away.

Can anyone at Sophos test and let us know what is going on with Windows 2016 Domain Controller compatibility?

Thank You



This thread was automatically locked due to age.
  • Joseph, you should go ahead and get a case started with Sophos Support.  While you're waiting on them to respond, check to see that NTLMv1 is enabled.  If it is, please post a few lines from the log where the join failed.

    Cheers - Bob