1

Administrator User Disabled

We keep seeing that our Clarity Administrator User keeps becoming disabled.  When this happens Clarity no longer runs any tasks.

We were going to upgrade to the newest version to see if that resolved the issue, but saw the email about the issue with 2022.1 and did not.  We are still a bit behind either way.  Below is our Server Version.

Clarity Version: 2022.0.7902

The Task Servers are on Build 2022.0.10.0   

Any help would be greatly appreciated.  Thanks

10 replies

Matt, i had our IT Director restart the task server services after fixing the user issue.  I will monitor to see if that fixes anything.

Just as a heads up, our Admin User was disabled again sometime in the last day or two.

Nick,

We’ve lately found one customer where it was related to the Clarity Windows Task Servers. The service needs to be restarted after changing the account credentials.

And it happened again sometime over the weekend.

This just happened again sometime over the weekend.  I just sent over the logs.

I will do that.  I had our IT Director update the Host Server yesterday, so I will keep an eye out for it and send those logs next time.  Thanks Matt.

This just happened again sometime in the last day or two.  This is pretty frustrating as when this happens all tasks stop.

Nick,

The next time you see it happen, please go to the Server/Logs page and send us all of the Clarity Website and Clarity Webservices log files.

(I presume that by the time you see this, it might be too late to get the Clarity Webservice log files, because they might have "rolled over" by then).

Thanks!

According to this there have only be 3 failed logins since 7/1.  i would expect to see a lot more if this is what is triggering it to become disabled right?

Nick - correct, that does seem odd.

You would need to have, I think 4 consecutive invalid logins to disable the admin.

I am sure I am missing something.  This is all I see on that page.  I don't see a way to filter a log type on there.

There's a little "funnel" icon next to each column header, if you pick it, it'll offer the available options to filter to.

Thanks for the reply Matt.  We are not currently using Active Directory Sync, so that would rule that out I assume correct?

I looked under the Logs you suggested and didn't find much to be able to look through.  Where would that User be signing in on a task server?  Is that something that would show up in log on the task server machine itself?

Nick,

Correct - that rules out ADSync.

When you setup a task server, you put in credentials to enable the task tray to sign in and retrieve the available tasks.

If you go to the Server / Logs page, then within that, there's a tab called "Application".

Then you can filter that on a date range, and on the type of log, like "LoginFailed".

image-1634825121309.png

Nick - the user can only become disabled via multiple failed sign in attempts.

We have often seen this issue when one of two systems has an "old" password in it, and is trying to sign in over-and-over:

- A Clarity Task Server
- The Clarity Active Directory Synch Service/Config

both of these are capable of trying to sign in repeatedly. If it's hard to figure out from just this description, you can also go into the Clarity/Server/Logs/Application tab - you can search for invalid password or disabled, and I think it will tell you the IP address of where the bad sign in was from.