I have AD integration configured for several years. I use it for both content filtering policies and VPN authentication.
The AD servers are Server 2012 R2 domain controllers. I noticed two of then were producing tls errors in the dashboard.
When I looked at the server, I see DCOM error Event ID 10036:
The server-side authentication level policy does not allow the user <domain admin account> SID (S-1-5-21-71189414-624380436-382417117-21771) from address <MX IP Address> to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.
Meraki stated the issue is with Microsoft Security and provided this link:
https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-...
I did not have success with the reg hack the article references, so I again asked support for help.
I received this from Meraki Support:
"After talking to our development team it looks like there is an update in the works for the AD integration but there is no current ETA on when that will be released. In the meantime, we suggest updating the registry key outlined in the following article by Microsoft."
https://docs.microsoft.com/en-us/answers/questions/564347/server-2019-update-kb5005568-sept-2021-for...
Has anyone else seen this issue with an MX an AD integration?