NetWorker:Active Directory 使用者無法登入 NetWorker,LDAP 錯誤代碼 49 Data 52f

Summary: Active Directory 使用者無法登入 NetWorker 和 NMC。產生的錯誤為「使用者名稱或密碼不正確」。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Active Directory 使用者無法在 NetWorker 命令列或使用者介面 (NetWorker Management Console、NetWorker Web 使用者介面等) 中登入驗證。
nsrlogin 傳回錯誤 "incorrect username or password"; 但是,用戶的登錄名和密碼輸入正確。

authc-server.log 收到以下訊息:

Unable to get user by name '<user name>'. Reason: Incorrect result size: expected 1, actual 0

Failed to bind as <Distinguished Name of the user> Users: org.springframework.ldap.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c^@]; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c^@]
Linux: /nsr/authc/logs/authc-server.log
Windows : C:\Program Files\EMC NetWorker\nsr\authc-server\tomcat\logs\authc-server.log

嘗試在 NetWorker 中更新外部授權資源時,出現相同的錯誤訊息。

Cause

LDAP error code 49 表示身份驗證錯誤。
LDAP data error code 52f 表示帳戶限制阻止此用戶登錄。
49 52f 1327 ERROR_ACCOUNT_RESTRICTION

在這種情況下,用於將 NetWorker AUTHC 綁定到域控制器的 AD 使用者帳戶屬於「受保護的使用者」AD 組。
 

Resolution

執行下列其中一個動作:

  • 從受保護的使用者群組移除 AD 使用者帳戶。
  • 創建一個不屬於受保護使用者安全組的新AD用戶帳戶。新的 AD 使用者必須新增至已被授予 NetWorker 使用者角色的 AD 群組。
注意: 如果 AD 使用者不屬於受保護使用者群組,請諮詢您的網域管理員。LDAP 錯誤 49 Data 52f 是從網域控制站傳回的限制存取錯誤代碼。

Additional Information

下列 AD PowerShell 命令會列出使用者所屬的 AD 群組: Get-ADPrincipalGroupMembership username | Select-Object Name

注意: 其中「 username 」是用來將 NetWorker 與 Active Directory 綁定的使用者帳戶。此命令需要安裝 Active Directory PowerShell 模組。默認情況下,這應包含在域控制器上。
PS C:\Users\Administrator> Get-ADPrincipalGroupMembership Administrator | Select-Object Name

Name
----
Domain Users
Administrators
Schema Admins
Enterprise Admins
Domain Admins
Group Policy Creator Owners
Protected Users
Organization Management
EMC App Agent Exchange Admin Roles

如需受保護使用者群組的詳細資訊,請參閱 https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group 此超連結會帶您前往 Dell Technologies 以外的網站。

如需額外的安全性,請設定 NetWorker 使用 LDAPS 而非 LDAP。

Affected Products

NetWorker

Products

NetWorker Family
Article Properties
Article Number: 000221735
Article Type: Solution
Last Modified: 11 أغسطس 2026
Version:  3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.