

Failed to enroll for the DirectAccess OTP logon certificateĮrror received (client event log).

Make sure that the Internet connection on the client computer is working, and make sure that the DirectAccess service is running and accessible over the Internet. The client computer cannot access the DirectAccess server over the Internet, due to either network issues or to a misconfigured IIS server on the DirectAccess server. Ī response was not received from Remote Access server using base path and port. User credentials cannot be sent to Remote Access server using base path and port.
WEBTREES FAILED TO AUTHENTICATE WINDOWS
Make sure that the client computer has established the infrastructure tunnel: In the Windows Firewall with Advanced Security console, expand Monitoring/Security Associations, click Main Mode, and make sure that the IPsec security associations appear with the correct remote addresses for your DirectAccess configuration.Ī connection cannot be established to Remote Access server using base path and port. Make sure that the CAs are configured as a management servers: Get-DAMgmtServer -Type All Get the list of configured OTP issuing CAs and check the value of 'CAServer': Get-DAOtpAuthentication On the DirectAccess server, run the following Windows PowerShell commands:
WEBTREES FAILED TO AUTHENTICATE PASSWORD
The user provided a valid one-time password and the DirectAccess server signed the certificate request however, the client computer cannot contact the CA that issues OTP certificates to finish the enrollment process. OTP certificate enrollment for user failed on CA server, request failed, possible reasons for failure: CA server name cannot be resolved, CA server cannot be accessed over the first DirectAccess tunnel or the connection to the CA server cannot be established. User fails to authenticate using OTP with the error: "Authentication failed due to an internal error"Įrror received (client event log). Failed to access the CA that issues OTP certificates Make sure that this log is enabled when troubleshooting issues with DirectAccess OTP.

DirectAccerss OTP related events are logged on the client computer in Event Viewer under Applications and Services Logs/Microsoft/Windows/OtpCredentialProvider. This topic contains troubleshooting information for issues related to problems users may have when attempting to connect to DirectAccess using OTP authentication. Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016
