cancel
Showing results for 
Search instead for 
Did you mean: 

User lock in LDAP: unclear UME error message

Former Member
0 Kudos

Hi all,

After reading through several sap notes and help pages, I thought I might get some help from the community

Setup

  • SAP portal (based on Netweaver 7.01 SP7)
  • Active directory has been configured as an LDAP datasource according to the SAP documentation:

http://help.sap.com/saphelp_nw70ehp2/helpdata/en/48/d1d13f7fb44c21e10000000a1550b0/content.htm?frame...

  • Where possible security parameters are synchronized between active directory and the SAP UME (password length, minimum alphanumeric characters,...)
  • Password lock is enforced by Active Directory as user management is done within this environment.

Issue

If a user enters a password incorrectly 5 times in a row the active directly user is locked. However the error message within SAP portal does not reflect this. It remains the same

User authentication failed

This is very confusing for the end user and consequently also for first line support handling tickets.

Is there some way to change the error message depending on the user lock.

Any other suggestions to solve this are of course also welcome.

Kind regards,

Tom Willems

Accepted Solutions (1)

Accepted Solutions (1)

bxiv
Active Contributor
0 Kudos

I think you would have to customize this, by querying LDAP for the status of the account (I think its a binary value) and then display a different error message.

Some food for thought, is it possible to switch to https and set IE to see the URL as a trusted system and pass the log in information to the server?  If an account is locked then the session should fail and would be less auths for the end user, if it just signs in for them; similar to SharePoint from M$.

Former Member
0 Kudos

Hi Billy,

Thank you for your answer.

I think I will look into your second suggestion.

Customizing the logon process doesn't sound like a very good idea in the long run.

Regards,

Tom

Answers (0)