Assume the following scenario:
- An NDES server is configured on the network.
- When calling the NDES administration web page (certsrv/mscep_admin) is not possible.
- After several unsuccessful login attempts, the following HTTP error message is returned:
401 - Unauthorized: Access is denied due to invalid credentials. You do not have permission to view this directory or page using the credentials that you supplied.
The Network Device Enrollment Service (NDES) provides a way for devices that do not have an identifier in Active Directory (for example, network devices such as routers, switches, printers, thin clients, or smartphones and tablets) to request certificates from a certification authority. For a more detailed description, see the article "Network Device Enrollment Service (NDES) Basics„.
Possible causes
Do you know TameMyCerts? TameMyCerts is an add-on for the Microsoft certification authority (Active Directory Certificate Services). It extends the function of the certification authority and enables the Application of regulationsto realize the secure automation of certificate issuance. TameMyCerts is unique in the Microsoft ecosystem, has already proven itself in countless companies around the world and is available under a free license. It can downloaded via GitHub and can be used free of charge. Professional maintenance is also offered.
- The user logging in has entered an incorrect password.
- A login restriction is configured for the logging in user account.
Details: A login restriction is configured for the logging in user account
The behavior can occur if a logon restriction is set in the logon user's account, for example, the userWorkstations Active Directory Attribute.
Microsoft recommendsto stop using the attribute.
The attribute can be queried via Windows PowerShell with the following command:
Get-ADUser -Identity {account name} -Properties userWorkstations
Related links:
External sources
- User workstations attribute (Microsoft)
One thought on “Die Anmeldung an der Administrations-Webseite für den Registrierungsdienst für Netzwerkgeräte (NDES) schlägt fehl mit HTTP Fehlercode 401 „Unauthorized: Access is denied due to invalid credentials.“”
Comments are closed.