Skip to content

Machine joined Active Directory but users are not resolved (SSSD)

If a node has joined Active Directory but you cannot resolve AD users on it, the problem is usually in the SSSD configuration. SSSD is the service that lets Linux look up users and groups from Active Directory.

Confirm the symptom

First, confirm the machine is joined to the domain:

realm list

If realm list shows your domain but looking up a user returns nothing, you have this problem:

getent passwd <USER_NAME>

When the join is fine but getent returns nothing, AD users cannot be resolved on the node.

Check the SSSD configuration and logs

Review the SSSD configuration file and its logs:

# Configuration
cat /etc/sssd/sssd.conf

# Logs
ls -l /var/log/sssd/
grep -riE "error|fail" /var/log/sssd/

Fix: enable ID mapping when the AD schema has no POSIX attributes

If SSSD is running, the most common cause is that your Active Directory schema does not include the uidNumber and gidNumber attributes, so SSSD has no POSIX IDs to map users to.

Edit /etc/sssd/sssd.conf and change ldap_id_mapping from False to True:

[domain/<YOUR_DOMAIN>]
ldap_id_mapping = True

Then restart SSSD and flush its cache:

systemctl restart sssd
sss_cache -E

Now the lookup should return the user:

getent passwd <USER_NAME>

Hybrid Linux and Windows access with FSx for NetApp ONTAP

Enabling ldap_id_mapping makes SSSD generate POSIX IDs itself instead of reading them from Active Directory. This causes ACL problems when you use FSx for NetApp ONTAP for hybrid Linux and Windows access, because the IDs SSSD generates will not match the ones the filesystem expects.

For correct behavior with a hybrid filesystem, keep ldap_id_mapping = False and make sure Active Directory provides the uidNumber and gidNumber attributes for your users and groups.