Data Domain: Active Directory Authentication not working because the global catalog is disabled

Summary: Active Directory (AD) Authentication not working because the global catalog (GC) is disabled in Data Domain.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Unable to log in.

Active Directory (AD) has been successfully configured.

The following commands provide a list of the AD users and groups:

cifs troubleshooting list-users 
cifs troubleshooting list-groups 
 
Checking an Admin AD user with the following command is successful:
cifs troubleshooting user <AD-User>

Cause

Cause:

Active Directory (AD) Authentication does not work if the global catalog (GC) is disabled in Data Domain.

Verification:

Check the output of the "cifs troubleshooting domaininfo" command.

For example:

cifs troubleshooting domaininfo
 
LSA Server Status:

Compiled daemon version: 6.4.2.0
Packaged product version: 6.4.0.70728
Uptime:        0 days 0 hours 6 minutes 5 seconds

[Authentication provider: lsa-activedirectory-provider]

        Status:        Online
        Mode:          Un-provisioned
        Domain:        XX.COM
        Domain SID:    S-1-5-21-326852099-1603424837-312552118
        Forest:        YY.COM
        Site:          xxxxxx

        Online check interval:  300 seconds

        [Trusted Domains: 28]

    [Domain: PART]

                DNS Domain:       YY.com
                Netbios name:     PART
                Forest name:      YY.com
                Trustee DNS name: XX.com
                Client site name:
                Domain SID:       S-1-5-21-2025429265-448539723-725345543
                Domain GUID:      0b13dbf9-d636-9c4e-ae15-d54243951480
                Trust Flags:      [0x0027]
                                  [0x0001 - In forest]
                                  [0x0002 - Outbound]
                                  [0x0004 - Tree root]
                                  [0x0020 - Inbound]
                Trust type:       Up Level
                Trust Attributes: [0x800000]
                Trust Direction:  Twoway Trust
                Trust Mode:       In my forest Trust (MFT)
                Domain flags:     [0x0022]
                                  [0x0002 - Offline]
                                  [0x0020 - GC offline]
 

From this output, the primary domain is reporting offline while the user is trying to access.

  • The forest (YY.COM) GC seems to be the issue.

Resolution

In DD-CLI (SSH), Disable the Global Catalog query on the Data Domain system:

cifs option set global-catalog-query-disable true 

Affected Products

Data Domain

Products

Data Domain
Article Properties
Article Number: 000081183
Article Type: Solution
Last Modified: 02 يونيو 2026
Version:  5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.