[IAG] Domain monitoring single sign-on failed: wmi service is not enabled
Problem Description
Single sign-on is configured, the user is obtained but single sign-on fails. The account has the highest authority except the administrator account.
Process——
- Check the domain monitoring acquisition time is the previous time, and no domain users have been obtained recently!
468165b87fd51cbb70.png (17.23 KB) - The account can log in to the domain server normally
- Use the Windows built-in tool wbemtest to test the connection and the prompt is rejected
- Log in to the AD domain to check the wmi control prompt service is not turned on. After turning it on, the account can read the domain user normally.

139585b87fdd241252.png (251.88 KB)
solution
The account has WMI permissions enabled, and the service is enabled. Domain monitoring single sign-on is normal.
Original Link
https://support.sangfor.com.cn/cases/list?product_id=22&type=1&category_id=6413&isOpen=true