No domain logon option after update


hi,

after updating new update windows 10. updated no issues did normal reboot , on login no longer have domain option windows live login screen. if switch users asks email address , not take domain\username. have removed , readded domain , reboot/google no avail. can still see profile , files no issue there can not authenticate.

anybody else having issue?

i've managed isolate how reproduce issue.  appears bug when combining group policy options interactive logon: message, , wireless network policies: single sign on type.

i started fresh install using enterprise build of 9879.  installed pending updates, , joined domain.  before rebooting, placed in ou blocked inheritance, , gpo 2 policies.  system boot once , allow me log in via domain account.  upon rebooting, option log in missing.  can view relevant gpo  below 3 relevant settings bolded.

it appears bug report needs filed.  in meantime, appears easiest thing create gpo windows 10 systems overwrites wireless sso setting.


computer configuration (enabled)
policies
windows settings
security settings
local policies/security options
interactive logon
policy setting
interactive logon: message text users attempting log on message
interactive logon: message title users attempting log on "some title"

wireless network (802.11) policies
test policy
policy name test policy
policy description sample description
policy type windows vista , later releases
global settings
use windows wireless lan network services clients enabled
shared user credentials network authentication disabled
hosted networks enabled
allow user view denied networks enabled
allow create user profiles disabled
use group policy profiles allowed networks disabled

network filters
prevent connection infrastructure networks disabled
prevent connection adhoc networks disabled
allowed networks
network name (ssid) network type
awscorp infrastructure

preferred network profiles
corp

profile name corp
network type infrastructure
automatically connect network enabled
automatically switch more preferred network enabled
    
network name (ssid) network broadcasts ssid
corpssid true
security settings
authentication wpa2
encryption aes
use 802.1x enabled
pairwise master key (pmk) caching enabled
pmk time-to-live (minutes) 720
number of entries in pmk cache 128
maximum pre-authentication failures 3

ieee 802.1x settings
cache user information subsequent connections network disabled
computer authentication user re-authentication
maximum authentication failures 1
maximum eapol-start messages sent  
held period (seconds)  
start period (seconds)  
authentication period (seconds)  
single sign on type prelogon
maximum acceptable delay network connectivity 10
network uses different vlan authentication computer , user credentials disabled
allow additional dialogs during single sign on enabled
network authentication method properties
authentication method protected eap (peap)
validate server certificate disabled
enable fast reconnect enabled
disconnect if server not present cryptobinding tlv disabled
enforce network access protection disabled
authentication method configuration
authentication method secured password (eap-mschap v2)
automatically use windows logon name , password(and domain if any) enabled

administrative templates
policy definitions (admx files) retrieved central store.system/group policy
policy setting comment
configure user group policy loopback processing mode enabled  
mode: replace
 

user configuration (enabled)
no settings defined.




Windows 10 Insider Preview  >  Windows 10 Insider Preview General



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Domain migration ERR3:7075 Failed to change domain affiliation, hr=8007054a This operation is only allowed for the Primary Domain Controller of the domain

How do a find data in one file, search for it in another file and if not found, write a custom message to another file