On One Identity Safeguard for Privileged Sessions (SPS), the appliance may appear as not joined to the Active Directory domain even though the domain membership itself remains valid. When the issue occurs, SPS reports that the appliance is not joined to the domain, and administrators may observe Kerberos keytab related errors. The following symptoms may be present:
This issue is caused by a defect in the SPS domain join/keytab refresh process.
STATUS
Change Request #492318 has been created to address this issue in a future release of SPS, subject to successful QA testing and product management approval.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center