Certificate-based authentication failing for domain-joined devices

Anthony Montaleone 0 Reputation points
2025-11-05T17:48:00.7666667+00:00

We have successfully setup Certificate Base Authentication with our Hybrid environment. Many months later we are unable to log in locally using certificates. We get 2 errors when trying to log in.

  1. Signing in with a smart card isn't supported for your account.
  2. Untrusted Certificate Authority

I have run so many verification cmd lines to check everything under the sun and still cant find an issue.

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. VPHAN 11,040 Reputation points Independent Advisor
    2025-11-05T18:25:35+00:00

    The first error means the user account is not configured for smart card logon, the second one means the certificate chain used for authentication is no longer trusted by the local machine or domain. In a hybrid environment, this usually happens when certificate trust or mapping has drifted since initial setup.

    To fix them, you need to verify the certificate chain (Ensure the full chain up to the root CA is present in trusted root certification authorities.) Check User Account Configuration (Confirm that the account is enabled for smart card logon and that the certificate is mapped (via UPN or altSecurityIdentities). If the certificate was reissued, you must update the mapping). Then validate CA Trust in the Domain, and check revocation settings (If the CRL expired, publish a new one from your CA).

    If you find this information useful to some extent, don't forget to accept the answer so that your experience with the issue would help contribute to the whole community. Thank you :)

    Vivian

    0 comments No comments

  2. VPHAN 11,040 Reputation points Independent Advisor
    2025-11-06T01:40:32.6133333+00:00

    Hi Anthony Montaleone,

    Have you found the core issue yet? Please let me know if I can assist further.

    Vivian

    0 comments No comments

  3. VPHAN 11,040 Reputation points Independent Advisor
    2025-11-13T01:24:43.1766667+00:00

    Good morning Anthony Montaleone,

    Just want to know how it is going with your issue? Should you need more information, feel free to leave a message. Happy to help :)

    Vivian

    0 comments No comments

  4. VPHAN 11,040 Reputation points Independent Advisor
    2025-11-23T08:43:23.0133333+00:00

    Hi,

    How is your issue? If you require more details or assistance, don’t hesitate to send a message. Glad to support you!

    VP

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.