Network Management

"Login failure. Windows Account not authorized" for SolarWinds Platform after upgrading to SolarWinds Platform 2020.2.6

After upgrading to SolarWinds Platform 2020.2.6, The SolarWinds Web Console login may fail when using Windows Authentication with Error: "Login failure. Windows Account not authorized."

First published date

7/28/2021 6:59 PM

Last published date

5/31/2025 10:56 PM

Overview

This article overviews what may be the possible causes for why you cannot log into the SolarWinds Web Console using Windows Authentication after upgrading to SolarWinds Platform 2020.2.6.  The error message will be the following:

Login failure.
Windows Account not authorized

 

Windows login failure.jfif
 

If this problem occurs, review the OrionWeb.log for the following error message:

INFO SolarWinds.Orion.Web.AuthorizationManager - (null) WindowsAuthorizationManager.CheckCreateUser() failed: System.ArgumentNullException: Value cannot be null. Parameter name: principalName
at SolarWinds.Orion.Web.Authentication.Windows.SecurityGroup..ctor(SecurityIdentifier sid, String principalName)
at SolarWinds.Orion.Web.AuthorizationManager.WindowsAuthorizationManager.GetGroupFromIdentity(IdentityReference groupIdent)
at SolarWinds.Orion.Web.AuthorizationManager.WindowsAuthorizationManager.CheckGroupMembership(WindowsIdentity identity)
at SolarWinds.Orion.Web.AuthorizationManager.WindowsAuthorizationManager.GetUpdatedVirtualUserFromGroupMembership(WindowsIdentity identity, String errorMessage)
at SolarWinds.Orion.Web.AuthorizationManager.WindowsAuthorizationManager.CheckCreateUser(WindowsIdentity identity)
at SolarWinds.Orion.Web.AuthorizationManager.CheckCreateUser(IIdentity identity) 

Product section

Orion Platform

Cause


This issue impacts only SolarWinds Platform 2020.2.6 due to introduced multiple changes to how group authentication is handled within the SolarWinds platform. See the following for some of the potential reasons why you may be running into issues:

  1. Customers are using the Primary group setting for groups used in SolarWinds platform. The Primary group is a legacy concept from Windows 2000 times not often used in modern environments, and the Windows group membership feature doesn't handle it correctly.
  2. Customers who turned off all Global catalogs (GC) in their AD environment. This isn't recommended by Microsoft and such customers should be informed that we aren't supporting environments with no GC enabled.
  3. Customers who are in their environment are using accounts from multiple Active Directory forests in the SolarWinds Platform.

Resolution

To resolve this issue, please upgrade to SolarWinds Platform 2020.2.6 HF2 and above.

There are multiple potential resolutions for this:

  • Do not use the 3 settings indicated above (IE: Primary groups, disabling Global Catalog)
  • Use Advanced AD/LDAP  
  • Reach out to SolarWinds Support, and ask about the possible authentication fallback query option to run against the database