NetWorker:Active DirectoryユーザーがNetWorkerにログインできない、LDAPエラー コード49データ52f

Summary: Active Directoryユーザーは、NetWorkerおよびNMCにログインできません。「ユーザー名またはパスワードが正しくありません」というエラーが生成されます。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Active Directoryユーザーは、NetWorkerコマンド ラインまたはユーザー インターフェイス(NetWorker管理コンソール、NetWorker Webユーザー インターフェイスなど)でログ認証を行うことはできません。
nsrlogin エラーを返します "incorrect username or password"; しかし、ユーザーのログオン名とパスワードは正しく入力されました。

この authc-server.log 次のメッセージがログに記録されました。

Unable to get user by name '<user name>'. Reason: Incorrect result size: expected 1, actual 0

Failed to bind as <Distinguished Name of the user> Users: org.springframework.ldap.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c^@]; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c^@]
Linux: /nsr/authc/logs/authc-server.log
Windows: C:\Program Files\EMC NetWorker\nsr\authc-server\tomcat\logs\authc-server.log

NetWorkerで外部認証機関リソースを更新しようとすると、同じエラー メッセージが表示されます。

Cause

LDAP error code 49 は認証エラーを意味します。
LDAP data error code 52f は、アカウントの制限により、このユーザーのサインインが妨げられていることを意味します。
49 52f 1327 ERROR_ACCOUNT_RESTRICTION

このシナリオでは、NetWorker AUTHCをドメイン コントローラーにバインドするために使用されるADユーザー アカウントは、「Protected Users」ADグループに属していました。
 

Resolution

次のいずれかのアクションを実行します。

  • 保護されたユーザー グループからADユーザー アカウントを削除します。
  • Protected User Security Groupに含まれていない新しいADユーザー アカウントを作成します。新しいADユーザーは、NetWorkerユーザー ロールが付与されているADグループに追加する必要があります。
メモ: ADユーザーがProtected Usersグループに属していない場合は、ドメイン管理者に問い合わせてください。LDAPエラー49データ52fは、ドメイン コントローラーから返される制限付きアクセス エラー コードです。

Additional Information

次のAD PowerShellコマンドは、ユーザーが属するADグループを一覧表示します。 Get-ADPrincipalGroupMembership username | Select-Object Name

メモ: ここで、 username は、NetWorkerをActive Directoryにバインドするために使用されるユーザー アカウントです。このコマンドを実行するには、Active Directory PowerShellモジュールがインストールされている必要があります。これは、ドメイン コントローラーにデフォルトで含まれている必要があります。
PS C:\Users\Administrator> Get-ADPrincipalGroupMembership Administrator | Select-Object Name

Name
----
Domain Users
Administrators
Schema Admins
Enterprise Admins
Domain Admins
Group Policy Creator Owners
Protected Users
Organization Management
EMC App Agent Exchange Admin Roles

保護されたユーザー グループの詳細については、「https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group 」を参照してください このハイパーリンクをクリックすると、デル・テクノロジーズ以外のWebサイトにアクセスします。

セキュリティを強化するために、LDAPではなくLDAPSを使用するようにNetWorkerを構成します。

Affected Products

NetWorker

Products

NetWorker Family
Article Properties
Article Number: 000221735
Article Type: Solution
Last Modified: 11 أغسطس 2026
Version:  3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.