Cannot join host to an AD realm with error - adcli: couldn't connect to example.com domain: Couldn't get kerberos ticket for: aduser@example.com: KDC reply did not match expectations
Issue
- AD user has insufficient access to join the domain via realmd/adcli:
Failed to join domain: Failed to set password for the machine account ( NT_STATUS_ACCESS_DENIED) <----
! Insufficient permission to join the domain example.com.
...
adcli: couldn't connect to example.com domain: Couldn't get kerberos ticket for: aduser@example.com: KDC reply did not match expectations
Environment
- Red Hat Enterprise Linux 8
- Microsoft Active Directory
- realmd
- adcli
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.