web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

No record found.

News and Announcements icon
Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Suggested Answer

NAV2016: Authentication error for a web service since the windows server patch Jan 2022

(0) ShareShare
ReportReport
Posted on by 5

Hello,

we are running Navision 2016 on a windows server 2016 OS.

After installing the cumulate Patch from January 2022 our web service brings an error.
I found this: KB5011233: Protections in CVE-2022-21920 may block NTLM authentication if Kerberos authentication is not successful (microsoft.com)

It seems that we have a authentication problem. Because we have enabled NTLM inside the NAV instance.

But when I now disable NTLM it still will not work.

I can see inside the events errors from LSA:
"The program Microsoft.Dynamics.Nav.Server.exe, with the assigned process ID 10036, could not authenticate locally by using the target name HTTP/xxxxx:7147.
The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name."

It is still there. I put an SPN in for the Navision server, but has not worked.

Did anyone have the same problem or have an idea for the solution?

Best Regards
Frank


I have the same question (0)
  • Suggested answer
    YUN ZHU Profile Picture
    99,086 Super User 2026 Season 1 on at
  • FrankinBerlin Profile Picture
    5 on at

    Hi ZHU,

    thank you for your answer.

    It give me more ideas.

    But we have published a dns name for the webservice in the internet (nav2sm.xx.org) and we route via firewall them to the nav server (nav01.yy.intern).

    So the event say it comes an request from HTTP\nav2sm.xx.org.

    I set a SPN for nav2sm.xx.org and nav2sm. But it will not work.

    Also not a SPN for nav01.yy.intern and nav01.

    Now i want to redirect the traffic on the Firewall to nav01.yy.intern.

    I am trying.....;-)

    Do you have an idea more?

    Frank

  • Suggested answer
    Marco Mels Profile Picture
    Microsoft Employee on at

    Hello,

    There may be two issues here:

    Please verify this blog:

    docs.microsoft.com/.../accessing-server-locally-with-fqdn-cname-alias-denied

    It is still required if you are using a different url to get to the WebClient.

    The November 2021 patch for Windows has an issue. You need an out of band hot fix for it as it has an issue with the constrained kerberos authentication.

    Hope it helps.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Stars!

Meet the Microsoft Dynamics 365 Contact Center Champions

We are thrilled to have these Champions in our Community!

Congratulations to the March Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Small and medium business | Business Central, NAV, RMS

#1
OussamaSabbouh Profile Picture

OussamaSabbouh 1,993 Super User 2026 Season 1

#2
YUN ZHU Profile Picture

YUN ZHU 1,116 Super User 2026 Season 1

#3
Khushbu Rajvi. Profile Picture

Khushbu Rajvi. 557 Super User 2026 Season 1

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans