Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8095523
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 5, 20262026-06-05T21:09:34+00:00 2026-06-05T21:09:34+00:00

I am trying to figure out what is going on. Here is our setup:

  • 0

I am trying to figure out what is going on. Here is our setup:
We have four SQL servers that are in replication with each other.

We add a new user to Windows Active Directory and add them to a group that is in SQL Server that we have been using for ages.

The new user, when trying to authenticate using Windows authenication returns that error in the subject line. But, any users that were previously in Active directory work fine.

At one point I had gotten SQL Server “caught up” becauuse we had a group of users that could not log in because of this error. I did some changes to the SPNs and ended up making it so no one could log in. Then I realized how the SPNs were supposed to look and fixed it. Then I guess some magic happened and those users were able to authenticate. I thought it was fixed, but it is obviously not as we had to add one new user and they cannot authenticate.

What is interesting is that the user can authenticate with three out of the four SQL Servers. It is only this one server that is working incorrectly. I set up two SPNs for the SQl Service on this sql server.

They look like –

MSSQLSvc/[servername].[domain].local:1433

MSSQLSvc/[servername]:1433

These are actually registered to the Service account that we use for the SQL Servers. What is interesting is that I can’t find the SPNs for the servers that are working anywhere.

Any help would be appreciated!

Edit: Also, another point to note is that if I try to add the user directly as a login into SQL server. I right click Logins and click Add Login then click search. I then type in [Domain]\[Username] and click check names. It validates the name as being correct. Then I click OK. And then OK again, and it gives the Error Windows NT user or group ‘[Domain]\[Username]’ not found. Check the name Again.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-05T21:09:36+00:00Added an answer on June 5, 2026 at 9:09 pm

    I thought it was fixed, but it is obviously not as we had to add one
    new user and they cannot authenticate.

    The user has to relogin in order to pick up the new group. Otherwise, it’s kerberos ticket is still using the old group membership information in its PAC

    These are actually registered to the Service account that we use for
    the SQL Servers. What is interesting is that I can’t find the SPNs for
    the servers that are working anywhere.

    I think what happen is that you have one SQL Server with SPN setup properly while the other three SQL Servers with no SPN setup at all. So, you are going to use Kerberos on this particular server while NTLM on the other three.

    As mentioned before, when you are using Kerberos, you have to either purge the ticket using some tools or you have to relogin in order to pick up the new group membership. You can also try to lock the screen and then unlock it. If I remember correctly, this should also refresh the ticket.

    Unlike Kerberos, NTLM doesn’t carry the group memberhsip data. After SQL Server authenticated the user using NTLM, it will find the authenticated user’s group membership, including the new group you just added.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I can't figure out where I'm going wrong here. Trying to validate an email
I have been going mad trying to figure out why my scripts weren't working,
Odd problem, trying to figure out what is going on here with my fresh
I have been trying to figure out a way to manage our domains at
I'm really having a hard time trying to figure out what's going on here.
I can't figure out what's going on here... I'm trying to copy an array,
Trying to figure out what in the world is going on with IE7 and
I am going a bit nuts trying to figure out why the following won't
I'm going a little nuts trying to figure out how to use template inheritance
I am migrating to wcf and trying to figure out how I'm going to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.