-
The Authentication Method of the user is Domain.
- Check the diagnostic monitor logs on the Policy Server if there are any errors or warnings which are related to "LDAP".
- When you get an LDAP unknown error, use the AD Process Tool to view the logs.
-
When changing the user who is logged in to preboot as the enterprise Administrator or Authenticator on the policy server MMC and login MMC, you can see if there are errors in the diagnostic monitor logs.
- If no logs are created, use the diagnostic monitor tool to check the connection between PS and the agent.
-
The Authentication Method of the user is Fixed Password.
-
Check the diagnostic monitor logs on the Policy Server if there are messages under restful API:
Restful - http://{policy server address}:{port}/TMEEService/device/{device id}?action=authenticate
For example: AuthenticateUserOnDeviceFailed: Invalid user name or password
- If no logs are created, use the diagnostic monitor tool to check the connection between PS and the agent.
-
Check the enterprise log events for the following:
On the PolicyServer MMC, navigate to Console Root > QA1 > QA Group1 - Group > Log Events to view the following:
- FDE agent log shows the message "Device synchronized".
- FDE agent log shows the message "Unsuccessful logon using fixed password".
-
Policy Server agent shows the message "User unable to log on using LDAP Authentication Failed".
-
In diagnostic monitor logs, you will see these similar logs:
- Verify that the Num Lock and Caps Lock are working as expected in preboot.
-
Verify that the keyboard layout is working as expected in preboot.
- Check the language display on the upper right corner.
- Check the language code in the preboot log: preboot\var\log\keyboard-setup.log