Logon Restriction error in ADManager Plus

Last updated on:

Issue description

When newly created technicians attempt to log in to ADManager Plus, they encounter the following error message:

As logon restrictions are enforced, you can login using only the built-in accounts. Please contact your administrator for details.

Possible causes

This error occurs when the Impersonate as admin option is not enabled for a technician, and the technician has not logged in before the Force SAML option is enabled. Since the technician’s details are not stored in the product before the SAML enforcement, ADManager Plus cannot authenticate their identity, preventing their login.

Prerequisites

The technician must log in at least once using Active Directory credentials before enabling Force SAML if the impersonate as admin is not configured for the technician.

Resolution

Step 1: Disable Force SAML

  1. Log in to ADManager Plus as the default admin.
  2. Navigate to Delegation > Logon Settings > SSO Configuration.
  3. Uncheck the Force SAML option.
  4. Save the settings.

Step 2: Ask the technician to log in

  1. Instruct the affected technician to log in once using their AD credentials in ADManager Plus.
  2. Ensure that the login is successful and their details are registered in the product.

Step 3: Re-enable Force SAML

  1. Navigate to Delegation > Logon Settings > SSO Configuration.
  2. Re-check the Force SAML option.
  3. Save the settings.

Now, the technician should be able to log in using SAML authentication without encountering the error.

Tips

  • If Impersonate as admin is enabled, no manual login is required before enforcing SAML.
  • Ensure the Identity Provider (IdP) configuration in ADManager Plus matches the settings in your SAML provider.

How to reach support

If the issue persists, contact our support team here.