Security

User LDAP Authentication with "Log On To" Workstation AD Restriction

mzorzi
Splunk Employee
Splunk Employee

We configured SPLUNK to use Active Directory as authentication system. Problem occurs with users that have "Log On To..." restrictions on the AD to restrict they ability to logon into Splunk from only a particular workstation.

Such user is unable to logon to the SPLUNK system, and the message returned is "Invalid username or password".

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This seems to be a problem for many folks who use the "Log On To Workstation" restriction in conjunction with web-based applications (especially non-microsoft webapps using a non-IE browser). Some things that sound like they may work include:

  1. Set the machine running SplunkWeb as one of the machines the user is permitted to Log On to
  2. Set the AD Domain Controller as one of the machines the user is permitted to Log On to. Which is of course very undesirable.

It seems like this is the AD Domain controller actively denying logons. An all-Microsoft stack (IE in the browser, IIS on the server, and Active Directory) can solve this by passing Kerberos tickets from the client's workstation (where they have the log on right) through to web applications using NTLM / Domain authentication. (When it works, googling shows cases where apps like sharepoint don't handle this well either)

I think this is something that you should probably open a support case with Microsoft on. They will be best equipped to answer WTF AD is doing here.

If all else fails, define the user a local Splunk account using Splunk's native authentication. It stinks, but it works.

0 Karma

nmistry_splunk
Splunk Employee
Splunk Employee

is your splunk search head part of "log on to" computer group?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...