Problems with authentication on domain using smart card logon

D

Dragan Mišukić

Dear MS Support,



we're using Smart Card logon as second method of our users to sign into domain based PCs.

After latest Servicing Stack update (KB4586863) and Cumulative update (KB4586786), logon with smart card stopped working with this message: "This smart card could not be used. Additional detail may be available in the system log. Please report this error to your administrator".

We've done several things:


1) Deleted current Smart card driver and reinstalled it - Alcor Micro USB Smart Card reader - didn't helped

2) Tryed to uninstall specified updates using wusa.exe script in Command Prompt in elevated mode and in Power Shell and got reply: "Security Update for Microsoft Windows (KB4586863) is required by your computer and cannot be unninstaled".

3) Tryed to modifiy it using Local Group Policy Editor:

gpedit.smc (Run As Admin) / Computer Configuration / Administrative Templates / Windows Components /Smart Card

and enable feature: Turn on certificate propagation from smart card


Despite this troubleshooting, we haven't find any Microsoft related (TechNet or similar) link or blog where Event ID 5 (after we've searched Event Viewer) was described and resolution for this kind of error.


Endpoints whic experienced this kind of issue are Windows 10 PRO OS, versions 1909, 2004 and 20H2, latest builds.

Domain controllers are on Windows Server 2019 Standard OS version.


We have several PCs that haven't yet got those latests updates, and logon is working just fine on their PCs.

Please provide us help and navigate us what else can we troubleshoot further on since we're out of ideas.

Is the solution for this case to reset PC (installing clean OS version) or is there anything else we can do about this issue?


Thank you in advance for the provided help.


BR,

Dragan

Continue reading...
 
Back
Top Bottom