| Reason: Invalid response
 Radius response: Authentication rejected
 User-Name: testuser
 | Incorrect token response. | 
Verify the correct response is being entered. 
Check the response in the administration console. 
Check if PIN configured for user.  | 
| Reason: Account locked out due to invalid attempts
 Radius response: Authentication Rejected
 User-Name: testuser
 | User’s account is locked in Defender. | Use the Defender Administration Console to reset violation count for the user. | 
| Reason: Invalid password
 Radius response: Authentication Rejected 
 User-Name: testuser
 | Incorrect Active Directory password.  | Verify the correct password is being entered. | 
| authentication abandoned user testuser 
 | Session timed out while waiting for user response. | Verify connectivity between the client and the Defender Security Server on the configured RADIUS port. | 
| Reason: User not valid for this route
 Radius response: Authentication Rejected User-Name: testuser | This message can be caused by one of the following: 
User is not a member of the Access Node. 
User does not have a token. 
User is not a Defender user. 
There is no license available for the user. 
Client IP not permitted by the Access Node.  | 
Verify the members of the Access Node. 
Verify the user has a Defender token assigned. 
Verify that suitable licenses exist. 
Verify the IP.  | 
| Domain Search from CN=testuser,CN=Users,DC=child,DC=democor p,DC=local took 57 seconds
 LDAP failed (-1)finding user testuser
 | Active Directory search has failed. This can happen if, for example, the child domain is unavailable. | Verify that the Defender service account has sufficient permissions or is a member of the Domain Administrators group. | 
| LDAP failed (50) writing token data for CN=PDWIN1348400003,OU=Tokens,OU=Defender,DC=democorp,DC=local
 Failed to write token data to LDAP
 | The Defender service account does not have sufficient permissions in Active Directory to update the user’s token information. | Verify that the Defender service account has sufficient permissions or is a member of the Domain Administrators group. |