Quantcast
Channel: All Centrify Express posts
Viewing all articles
Browse latest Browse all 1833

Re: What does the error "This machine's subnet is not known by AD." actually mean?

$
0
0

,

 

Welcome back!

The message means that the  information in the "AD Sites and Services" is incomplete.

 

Some AD basics

AD leverages information about sites and subnets stored in AD to tell clients what's the "nearest provider" for a service.  One such service is authentication.  If the subnet that the system exists on, is not registered in AD, an authentication request for a system that is in California, may be fulfilled by a domain controller in Singapore (highly inefficient if the link between the sites is expensive).

 

From a process perspective, this may also indicate poor communication between the Networking and Directory Services teams.

 

The more complete the information in AD, the faster and more efficient the authentication, MFA or privilege elevation events will be.  This is one of the checks done by acheck.

 

 

Image result for ad subnets

 

 

R.P


Viewing all articles
Browse latest Browse all 1833

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>