# Authentication settings for active directory: sAMAccountName instead of userPrincipalName

**URL:** <https://discuss.elastic.co/t/authentication-settings-for-active-directory-samaccountname-instead-of-userprincipalname/247105>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 1, 2020, 2:16pm UTC](https://discuss.elastic.co/t/authentication-settings-for-active-directory-samaccountname-instead-of-userprincipalname/247105 "2020-09-01T14:16:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stanvv](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@Stanvv](https://discuss.elastic.co/u/Stanvv)\
**Post date:** [September 1, 2020, 2:16pm UTC](https://discuss.elastic.co/t/authentication-settings-for-active-directory-samaccountname-instead-of-userprincipalname/247105/1 "2020-09-01T14:16:23Z")

</div>

How can I configure logging in with `sAMAccountName` instead of `userPrincipalName` ?

We used the LDAP realm before, but due to the [lack of support](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-limitations.html#_ldap_realm) on nested groups switched to active\_directory realm with the following settings:

```
xpack:
  security:
    authc:
      realms:
        native:
          realm1:
            order: 0
        active_directory:
          ldap:
            order: 1
            url: "ldaps://ldap.abc.def:636"
            bind_dn: "CN=myusername,OU=Accounts,OU=MyApp,OU=Applications,OU=Groups,DC=abc,DC=def"
            user_search:
              base_dn: "DC=abc,DC=def"
              filter: "(sAMAccountName={0})"
              upn_filter: "(&(objectClass=user)(sAMAccountName={0}))"
            group_search:
              base_dn: "OU=Roles,OU=MyApp,OU=Applications,OU=Groups,DC=abc,DC=def"
            ssl:
              certificate_authorities: ["certs/my_cert.crt"]

```

The connection works fine, but I cannot seem to find how to configure authenticating with my `sAMAccountName` (e.g. 123456) rather than `userPrincipalName` (e.g. 123456@abd.def).

When I try to login with "123456" given the settings above, it says `Invalid username or password. Please try again`, while 123456@abd.def does work.

For the LDAP realm that was just setting `user_search.filter: "(sAMAccountName={0})"`.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 2, 2020, 6:26am UTC](https://discuss.elastic.co/t/authentication-settings-for-active-directory-samaccountname-instead-of-userprincipalname/247105/2 "2020-09-02T06:26:51Z")

</div>

Hi there. Please add the `domain_name: abd.def` to your realm settings

---

<div class="post-metadata">

**Author:** ![Stanvv](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@Stanvv](https://discuss.elastic.co/u/Stanvv)\
**Post date:** [September 2, 2020, 7:40am UTC](https://discuss.elastic.co/t/authentication-settings-for-active-directory-samaccountname-instead-of-userprincipalname/247105/3 "2020-09-02T07:40:16Z")

</div>

Thanks, this was indeed the issue!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2020, 7:40am UTC](https://discuss.elastic.co/t/authentication-settings-for-active-directory-samaccountname-instead-of-userprincipalname/247105/4 "2020-09-30T07:40:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
