SP 2019 - no longer able to add AD security group to Sharepoint Group for permissions

%3CLINGO-SUB%20id%3D%22lingo-sub-1543986%22%20slang%3D%22en-US%22%3ESP%202019%20-%20no%20longer%20able%20to%20add%20AD%20security%20group%20to%20Sharepoint%20Group%20for%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1543986%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20SP%202019%20on%20premise.%26nbsp%3B%20Recently%2C%20we%20attempted%20to%20add%20an%20AD%20local%20security%20group%20to%20a%20SP%20group%20to%20give%20permission%20to%20a%20collection.%26nbsp%3B%20The%20name%20resolves%20but%20when%20I%20hit%20the%20share%20the%20group%20does%20not%20show%20up%20in%20the%20permission%20list.%26nbsp%3B%20No%20indication%20of%20any%20action%20at%20all%20nor%20any%20errors%20that%20I%20could%20see.%26nbsp%3B%20We%20were%20able%20to%20last%20Tuesday%20as%20I%20see%20a%20group%20in%20there%20with%20that%20date%20added%20by%20our%20developer.%26nbsp%3B%20If%20we%20attempt%20to%20add%20an%20AD%20user%20to%20the%20permission%20group%20it%20works%20just%20fine.%26nbsp%3B%20This%20would%20be%20painful%20if%20we%20have%20to%20add%20users%20this%20way.%26nbsp%3B%20I%20believe%20there%20was%20an%20update%20ran%20over%20the%20weekend%20but%20need%20to%20confirm.%26nbsp%3B%20We%20checked%20other%20collections%20and%20seems%20to%20the%20same%20case%20throughout%20the%20entire%20site.%26nbsp%3B%20Is%20there%20anything%20I%20can%20check%20or%20verify%20as%20to%20why%20an%20AD%20sec%20group%20can%20no%20longer%20be%20added%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1543986%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1546876%22%20slang%3D%22en-US%22%3ERe%3A%20SP%202019%20-%20no%20longer%20able%20to%20add%20AD%20security%20group%20to%20Sharepoint%20Group%20for%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1546876%22%20slang%3D%22en-US%22%3ECan%20you%20check%20the%20ULS%20logs%20and%20see%20what%20log%20activity%20there%20is%3F%20You%20may%20need%20to%20set%20the%20log%20to%20verbose%2C%20Set-SPLogLevel%20-TraceSeverity%20Verbose.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1554034%22%20slang%3D%22en-US%22%3ERe%3A%20SP%202019%20-%20no%20longer%20able%20to%20add%20AD%20security%20group%20to%20Sharepoint%20Group%20for%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1554034%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F130%22%20target%3D%22_blank%22%3E%40Trevor%20Seward%3C%2FA%3E%26nbsp%3BHey%20Trevor%2C%20thanks%20for%20the%20response.%26nbsp%3B%20I%20looked%20at%20those%20logs%20and%20it%20looks%20like%20the%20user%20profile%20sync%20service%20account%20is%20not%20working.%26nbsp%3BThe%20account%20is%20not%20locked%20so%20I'm%20not%20sure%20if%20its%20a%20different%20issue%20as%20the%20error%20indicates%20a%20failure%20to%20decrypt%20the%20connection%20password.%26nbsp%3B%20I%20have%20not%20seen%20this%20error%20before.%26nbsp%3B%20I%20rather%20not%20change%20the%20password%20yet%20as%20I%20think%20my%20old%20sharepoint%20admin%20used%20it%20elsewhere%20which%20we%20are%20identifying.%26nbsp%3B%20Would%20this%20be%20related%20to%20my%20inability%20to%20add%20AD%20security%20groups%20to%20sharepoint%20permission.%3C%2FP%3E%3CP%3E%3CFONT%20face%3D%22Calibri%22%20color%3D%22%23000000%22%3EGeneral%207200%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20Critical%26nbsp%3B%26nbsp%3B%20Failed%20to%20decrypt%20connection%20password%20for%20ConnectionForectName%20'domain.local'%2C%20ConnectionSynchronizationOU%20'DC%3DSOG%2CDC%3DLocal'%2C%20ConnectionUserName%20'domain%5Caccount'.%20Please%20refresh%20connection%20credentials.%20a77c6a9f-4b17-a0cf-6cd8-e9f87678dff3%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

We have SP 2019 on premise.  Recently, we attempted to add an AD local security group to a SP group to give permission to a collection.  The name resolves but when I hit the share the group does not show up in the permission list.  No indication of any action at all nor any errors that I could see.  We were able to last Tuesday as I see a group in there with that date added by our developer.  If we attempt to add an AD user to the permission group it works just fine.  This would be painful if we have to add users this way.  I believe there was an update ran over the weekend but need to confirm.  We checked other collections and seems to the same case throughout the entire site.  Is there anything I can check or verify as to why an AD sec group can no longer be added?

5 Replies
Highlighted
Can you check the ULS logs and see what log activity there is? You may need to set the log to verbose, Set-SPLogLevel -TraceSeverity Verbose.
Highlighted

@Trevor Seward Hey Trevor, thanks for the response.  I looked at those logs and it looks like the user profile sync service account is not working. The account is not locked so I'm not sure if its a different issue as the error indicates a failure to decrypt the connection password.  I have not seen this error before.  I rather not change the password yet as I think my old sharepoint admin used it elsewhere which we are identifying.  Would this be related to my inability to add AD security groups to sharepoint permission.

General 7200                Critical   Failed to decrypt connection password for ConnectionForectName 'domain.local', ConnectionSynchronizationOU 'DC=SOG,DC=Local', ConnectionUserName 'domain\account'. Please refresh connection credentials. a77c6a9f-4b17-a0cf-6cd8-e9f87678dff3

 

Highlighted
Essentially that is saying you need to re-enter the credentials for the Sync account in the AD Import configuration screen.
Highlighted

We ran a full synchronization and it resolved this issue with the user profile sync.  We are still having the issue where we can only ad domain user accounts but not domain security group.  Is there any other way to troubleshoot this? 

Highlighted

We figured it out.  We ran a command for the people picker to our trusted 2nd domain and on sharepoint servers and not just frontends.  Needed to be ran on app server as well but had to find the app cred key from front ends and imported them.  Seems to work now.