Hi Percy Nguyen,
Thanks for the advice.
First, we would like to provide some additional observations regarding the issue.
During the affected sign-in flow, we observed an Application Log – Event ID 1000 occurring around the same timeframe as the Windows sign-in issue.
This environment uses Silverfort MFA for Windows Logon. The user first enters the Windows username and password, and then proceeds to an additional Silverfort MFA step, such as OTP verification or MFA enrollment.
We have observed the issue in the following scenarios:
- OTP / MFA Prompt
- The user has already entered the username and password successfully.
- The Silverfort OTP screen is displayed.
- While the user is waiting to enter the OTP, the popup error appears.
- The popup interrupts the authentication flow and prevents the user from entering the OTP.
- MFA Enrollment
- The user has already passed the username and password stage.
- The system proceeds to the Silverfort MFA enrollment step.
- Before the user can complete the enrollment, the popup error appears and the screen becomes unresponsive, preventing any further action.
- Local Administrator Sign-in
- The customer confirmed that when signing in with a Local Administrator account that does not require the Silverfort MFA/OTP flow, the Windows sign-in completes normally.
- The issue has not been observed in this scenario.
Based on the current observations, the issue appears to occur only when the account enters the Silverfort MFA/OTP or enrollment flow after the primary username/password authentication step.
At this stage, we are not concluding that Silverfort is the root cause, but the behavior appears to be associated with the additional MFA flow rather than with the initial Windows username/password authentication itself.