Hi,
I'm experiencing a very unusual issue. At first it was only me and I put it down to my laptop being ditzy, but now one of my users is experiencing the problem too which has got me spooked. Here's the deal:
We have multiple sites and will use 2 as illustrative examples; site A and site B and I'll start with site B first as this is where we are seeing the problem.
At site B we have a Server 2012R2 AD server. Affected users can log into their machines sometimes, but at other times the password will not be accepted; instead, the previous password for that user's account will be accepted. The issue is experienced when waking the laptop from sleep (our devices are set to prompt for password when waking from sleep by policy). The issue seems to get worse as the affected users spends more time at site B, but I have no measurable metric against which to confirm this; further it seems possible that if you type your password very soon after waking you can get in, but if you wait for a few seconds/for the wireless network connection to become established (not sure which) you won't be able to get past the login screen with the correct password. Further, if the affected users starts up their device at site B, only the 'wrong' password will be accepted and the OS will require the keychain to be updated - keychain will ask for the 'previous' (i.e. correct) password which, when entered, will update it to the wrong password. Once the wrong password has taken effect it is used to make changes to device settings (e.g. change time zone, etc.) as well as permitting login.
At site A we have a Server 2008R2 AD server. Users can log in to their device without issue at this site. If the affected user's keychain has been updated as described above, the process can be reversed from site B.
Note that, at site B, Windows 7-based devices do not suffer the issue; if the affected user logs into a Windows 7-based device they can do so with the correct password even if the macOS-based device is experiencing the issue. The issue will present itself on multiple macOS-based devices; the constants seem to be the site, the user and the device OS.
The number of users unaffected vastly outweigh those who are - only 2 known cases vs 200 working without issue.
Further, changing password through System Preferences on the local device is not possible at site B, giving an error message and refusing to proceed; no issues at site A, even when changing the password to the same string as attempted without success at site B.
Lastly, network services requiring login can be accessed from any site, including B, using the correct password. Only the local device is affected by the issue, even when the hosted service server is using a Server 2012R2 AD for authentication.
Lastly, the issue has also been observed at another site, site C, which also has 2012R2 as AD server. All servers are in the same domain and a comparison of affected user objects on the 2012R2 and 2008R2 server does not show any discrepancy.
The below describes how the laptop is configured.
macOS Sierra and High Sierra (issue observed on both)
FileVault enabled
Device bound to Active Directory (Create mobile account at login)
Issue happens only at sites with Server 2012R2 as AD server
Kerberos & RADIUS authentication is performed at login (network payload in Jamf Pro config profile)
Can anyone help identify the cause of the above issue?