<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000A1C2ZiCQKOkta Classic EngineDirectoriesAnswered2025-05-02T09:00:30.000Z2024-03-17T14:06:16.000Z2024-03-26T21:14:22.000Z

nhcd8 (nhcd8) asked a question.

Unable to install AD agent - Error while creating the service account

Good afternoon,

 

We are trying to install the AD Windows agent.

When the installer is creating the Service account, if fails with a blank error message (only a red cross).

 

We tried to add it manually, without success.

Even to add this account to Domain Admins is failing.

 

Is it a known issue ? Where can we find logs to understand better ?

 

Thanks for your help.

 

Evo


  • Mihai N. (Okta, Inc.)

    Hi @nhcd8 (nhcd8)​ , Thank you for reaching out to the Okta Community! 

     

    You can check for logs under (default installation location) C:\Program Files(x86)\Okta\Okta AD Agent\logs

     

    Please make sure you meet all the prerequisites: 

    https://help.okta.com/en-us/content/topics/directory/ad-agent-prerequisites.htm

     

    If those are met, take a look at the following posts in case you are encountering the same issue that is mentioned there: 

    https://support.okta.com/help/s/question/0D54z00008jV181CAC/okta-ad-agent-installation-is-failing-logs-show-service-okta-ad-agent-was-not-found-on-computer?language=en_US

     

    https://support.okta.com/help/s/article/Error-creating-service-account-Access-is-Denied-while-creating-a-service-account?language=en_US

     

    I also recommend doing a fresh install by clearing any previous Okta Agent data from your drive then running a new install. Files typically located in C:\Program Files(x86)\Okta\Okta AD Agent .  

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --------------------------------

    Ask the Experts: Okta Device Access Product Team Now Thru 3/22

    Expand Post
    Selected as Best
  • nhcd8 (nhcd8)

    Hi,

     

    Thank you for your answers.

     

    Log files show this :

    2024/03/17 17:55:43.480+01:00 Info -- XXXXX02(1) -- Creating service account OktaService@xxxxxx.xx

    2024/03/17 17:55:43.480+01:00 Warning -- XXXXX02(1) -- LookupAccountName failed: 1332

    2024/03/17 17:55:43.480+01:00 Warning -- XXXXX02(1) -- Could not find user OktaService@xxxxxx.xx in the forest

    2024/03/17 17:55:43.480+01:00 Info -- XXXXX02(1) -- Assuming SAM account name as xxxxxx.xx\OktaService

    2024/03/17 17:55:43.777+01:00 Info -- XXXXX02(1) -- Granting SeServiceLogonRight to XXXXXX\OktaService

    2024/03/17 17:55:43.777+01:00 Error -- XXXXX02(1) -- Unexpected error: A specified logon session does not exist. It may already have been terminated.

     

    2024/03/17 17:55:43.793+01:00 Info -- XXXXX02  at System.Security.Principal.WindowsIdentity.KerbS4ULogon(String upn, SafeAccessTokenHandle& safeTokenHandle)

      at System.Security.Principal.WindowsIdentity..ctor(String sUserPrincipalName, String type)

      at System.Security.Principal.WindowsIdentity..ctor(String sUserPrincipalName)

      at Okta.Agent.Installation.AgentCli.UserUtility.CheckSvcUserPermissions(String username)

      at Okta.Agent.Installation.AgentCli.ConfigCli.GenerateSvcUser()

      at Okta.Agent.Installation.AgentCli.ConfigCli.Execute(ConfigurationScope scope, String[] args)

    System.Security.SecurityException received with message A specified logon session does not exist. It may already have been terminated.

     Source=mscorlib InnerException=.

     

    All prerequisites are met, and we tried also with an existing Domain Admin account : No more success...

    Any idea with this extract of the log file ?

     

    Best regards,

     

    Sylvain

    Expand Post
    • Mihai N. (Okta, Inc.)

      At this point, I think it's safe to say that the issue is environmental, so if you have another server where you could test the install, I recommend trying it. 

       In the meantime, I've checked for any similar reports and here is what I found out that might help with the situation: 

       

       

      " agent installation issue is resolved after adding the install user into the local server admin and Okta URL to IE's Trusted Site. "

       

      OR

       

      " The error message you are seeing in the InstalUtil file is the SYSTEMLOGON operation response from verifying the AD service account. The error you are seeing shows there's either a constraint for using/creating users capable of using the systemlogon feature on the particular machine the agent is installed on. After logging in with the appropriate account, the installer finished successfully." 

       

       

       

       

       

      Regards.

      --

      Ask the Experts: Okta Device Access Product Team Now Thru 3/22

      Expand Post
  • n6x4w (n6x4w)

    I'm encountering the same issue. Attempting to install the AD Windows agent results in failure during the creation of the service account, displaying only a blank error message with a red cross icon. Moreover, if you want to download capcut mod apk then visit this website https://capcutproapk.org/. We've attempted manual addition of the account without success, even adding it to Domain Admins, which also fails.

    Expand Post
This question is closed.
Loading
Unable to install AD agent - Error while creating the service account