Question

AD User Account Deleted / Recreated = CS Account Disabled

  • 5 January 2023
  • 2 replies
  • 129 views

Badge +15

CS Version 11.24.78

Issue: User ad object was deleted from AD and then deleted from Commvault. Couple months later, same user was recreated with the same name, added to the same AD Groups however when attempting to login to CS Console I get “Account Disabled”

--------------------------------------------

EvMgrS.log

9236  2d50  01/06 04:32:50 ####### GetAvailableRedirectForUser() - No valid external authenticator found for user [DOMAIN\userlogin]
9236  2d50  01/06 04:32:50 ####### isUserAccountLocked() - Checking if account is locked for user DOMAIN\userlogin
9236  2d50  01/06 04:32:50 ####### CVGlobalParam::getProperty() - fetching for propName [FailedLoginAttemptLimit]
9236  2d50  01/06 04:32:50 ####### CVGlobalParam::getProperty() - fetching for propName [AccountLockDuration]
9236  2d50  01/06 04:32:50 ####### EvSecurityMgr::userLogin() - Socket [0x0000000000002EE0]: DISABLED ERROR: Account disabled.
9236  2d50  01/06 04:32:50 ####### ::sendResponse() - FAILED [Account disabled.]
9236  2d50  01/06 04:32:50 ####### handleLoginOperations() -  Encrypted Login Failed.Browser Session Id [72]

--------------------------------------------

  • User is not listed in the CommCell Users entity or in any entity under security.
  • Tried via webconsole/adminconsole and same Account Disable message. 
  • Tried to add the user back via CS Console and Webconsole, and get invalid domain.
    • Validated / Sync the domain no issues and other users from the domain can login just fine.
  • Tried the get_user_template.xml and I get “User not found or does not exists” 

Any suggestions?

 


2 replies

Userlevel 6
Badge +15

Good afternoon.  I believe this may be tied to the GUID of the user.  There may be a script that will resolve this but I will need to reach out to some of my Server team resources on Monday.  I will update this thread by end of day Monday.

Badge +15

@Orazan would you mind sharing the script you mentioned?

Reply