> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v3.0/help-and-support/support-articles/kb000005.md).

# KB000005: Access Manager stops working after applying the November 2022 Windows update

## Summary

After installing the November 2022 Windows updates on your domain controllers, you may find that the Access Manager service does not start, or user authentication fails when trying to access the web service.

## Cause

There are [known issues](https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#2953msgdesc) with the [November 2022 Windows update](https://support.microsoft.com/en-us/topic/november-8-2022-kb5019980-os-build-22621-819-b503e08b-b850-469a-8de9-74df8aebd5f4) that can prevent users, service accounts, and computer objects from authenticating in the domain.

This can result in the Access Manager Service failing to start, or if the service does start, the Access Manager service may be unable to access resources within the domain. As a result, users cannot log into the AMS website, or access LAPS password and request JIT access.

In the event log or in the AMS log files (`C:\Program Files\Lithnet\Access Manager Service\logs`), you may find one or more of the following log entries (or similar messages).

```
Lithnet.Security.Authorization.AuthorizationContextException: AuthzInitializeContextFromSid failed
 ---> System.ComponentModel.Win32Exception (0x80090342): The encryption type requested is not supported by the KDC.
```

```
System.Security.Authentication.AuthenticationException: The user name or password is incorrect.
 ---> System.Runtime.InteropServices.COMException (0x8007052E): The user name or password is incorrect.
```

Users may see an error message in the portal saying:

> Your request could not be processed because your SSO identity could not be found in the directory

## Resolution

Microsoft have released an out-of-band update to fix the known issue with the update. Install the update on all domain controllers, and once complete, reboot the AMS server.

* [KB5021656: Windows Server 2022](https://support.microsoft.com/help/5021656)
* [KB5021655: Windows Server 2019](https://support.microsoft.com/help/5021655)
* [KB5021654: Windows Server 2016](https://support.microsoft.com/help/5021654)
* [KB5021653: Windows Server 2012 R2](https://support.microsoft.com/help/5021653)
* [KB5021652: Windows Server 2012](https://support.microsoft.com/help/5021652)
* [KB5021657: Windows Server 2008 SP2](https://support.microsoft.com/help/5021657)

This patch does not need to be installed on the AMS server itself.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v3.0/help-and-support/support-articles/kb000005.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
