What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
If an SSRS report fails after a ConfigMgr upgrade with UserTokenSIDs and “Logon failure: unknown user name or bad password,” first identify the account running the Reporting Services service and check whether it can read the report user’s Active Directory group membership. The error is a symptom, not proof that the upgrade caused a universal SSRS regression: the original report of this issue did not reproduce in three environments and did not establish a root cause. Use the full error and SCCMReporting.log to choose the right fix.
Capture the complete error and find the reporting log
- Record the full message. Include the text after
UserTokenSIDs, especially whether it says “Logon failure: unknown user name or bad password,” “The specified directory service attribute or value does not exist,” or “The encryption type requested isn’t supported by the KDC.” Note whether the report fails in the ConfigMgr console, the SSRS portal, or both. - Identify the SSRS service identity. Check the account configured to run the Reporting Services service. Do not assume it is the same as the account configured for the ConfigMgr reporting point or an account running another SQL service.
- Inspect
SCCMReporting.log. Look in the Reporting Services service account’s%temp%folder. If SSRS runs under its default virtual service account, Microsoft gives this path:C:WindowsServiceProfilesSQLServerReportingServicesAppDataLocalTemp. The exact location depends on the service identity. Starting with Configuration Manager current branch version 2509, the log includes detailed information about the RBAC permission check; do not expect that detail on earlier versions.
Microsoft’s current troubleshooting guidance covers the RBAC group lookup and log interpretation in Reports don’t run when RBAC is enabled. The original upgrade-related report is described in HTMD’s July 26, 2024 post; its author said the issue did not reproduce in three environments and did not identify a confirmed cause.
Match the exact message to the cause
| Full error or log clue | What it points to | What to check |
|---|---|---|
UserTokenSIDs default-value error followed by “Logon failure: unknown user name or bad password” |
Possible failure to look up the report user’s AD group membership for ConfigMgr RBAC. | Whether the actual SSRS service account can read the report user’s group membership; check SCCMReporting.log and the relevant domain context. |
| “The specified directory service attribute or value does not exist” | A separate AD DS attribute or permission scenario documented for System Center 2012 R2. | Read permission on the OU containing the report user, or on the Users or Computers AD DS containers as applicable to that documented scenario. |
“The encryption type requested isn’t supported by the KDC” or KDC_ERR_ETYPE_NOSUPP |
A Kerberos encryption-type mismatch, not a Windows Authorization Access Group membership issue. | AES encryption support and valid AES keys for the actual service account. |
These messages are not interchangeable. Microsoft documents the AD attribute/container case separately in Reports don’t run as expected; that article is specifically framed around System Center 2012 R2. Use its permission advice only when the error and environment match, rather than treating it as the fix for every UserTokenSIDs failure.
For a group-membership lookup failure, verify access for the SSRS identity
ConfigMgr uses role-based administration (RBAC) to restrict report data. To evaluate a report user’s access, the Reporting Services service account needs to read that user’s group membership from Active Directory. The tokenGroupsGlobalAndUniversal attribute contains SIDs for the user’s global and universal groups. Windows Authorization Access Group membership is relevant because it grants access to that attribute.
#1 Best Overall
- Durability: This rack mount rail is made from cold-rolled steel, 4-port fixed can support a weight of up to 120lbs (54kg); Electrostatic powder coat preventing rust and corrosion
- Flexible Depth: Server rack shelf rail with adjustable depth from 20.9 to 32",suitable for racks of different depths
- Widly Application: Compared to the 19 "cantilever shelf, this half bracket rail has no width limit,can be applied to server racks of 10 ", 19 "and so on
- Ventilation:Vented shelves increases ventilation efficiency and heat dissipation to protect equipments long-term use
- Installation:Equipped with a complete set of accessories,and it is easy to install,with instruction or video for reference
- Confirm the service identity from the Reporting Services configuration; do not make a permission change based only on the reporting-point account or another SQL service account.
- Check the affected user’s domain and whether the confirmed SSRS identity can read the required group membership there.
- Use the log evidence to determine whether the lookup is failing, then verify the applicable Windows Authorization Access Group and attribute-access requirements with your AD administrator before changing membership or permissions.
- Retest the report as the affected user and review the log for the result.
Microsoft notes that virtual service accounts and machine accounts usually have this attribute access by default, so verify the actual identity and access instead of adding accounts to a group indiscriminately. The HTMD post recounts an older forum example in which adding the SQL service account resolved the issue while adding a different account did not; that is an environment-specific anecdote, not a general requirement.
If the KDC reports an unsupported encryption type
Do not treat KDC_ERR_ETYPE_NOSUPP as an AD group-membership problem. Microsoft says this error indicates a Kerberos encryption-type mismatch. Its guidance describes a Kerberos request to a domain controller’s KDC while Windows creates an identity for the report user.
Rank #2
- Sturdy:4u server rack is construct from cold rolled steel, with a weight capacity of 110lbs(50kg); Electrostatic powder coat prevents rust and corrosion,quality finish
- Direct use:Open and use, not having to assemble it.Network rack can be placed flat or mounted on the wall,also can be installed vertically under the table
- Design Features:maximum mounting depth of 14 in,cables can be fixed on the side panel;Open frame server rack achieves effortless inspection, replacement and assemble
- Installation:wall mount network rack is easy to install,with instructions or videos for reference;Equipped with multiple accessories, suitable for different needs
- Application:EIA/ECA-310-E Compliant;wall mounted 4u rack fits all 19" racks and cabinets to hold various IT, network, and AV equipment;wall mount rack available in 4U, 6U, and 8U to choose
Microsoft’s 2026 Windows security-update guidance phases out RC4 as the default: January introduced auditing and preparation controls; the April update changes DefaultDomainSupportedEncTypes to 0x18 for accounts without explicit configuration, enabling AES128 and AES256; and the July update removes Audit mode and the temporary rollback control. For an affected service account, Microsoft recommends enabling AES 128 and/or AES 256 support and ensuring the account has AES-SHA1 keys. If needed, change the account password to generate the keys and update the SSRS service credentials, then retest. Follow Microsoft’s current instructions for your Windows and ConfigMgr versions; do not broadly re-enable RC4 as a shortcut. See the dated guidance in Reports don’t run when RBAC is enabled.
Keep RBAC enabled while diagnosing
Avoid using EnableRbacReporting=0 as a routine fix. Microsoft notes that the registry value reverts to 1, and disabling RBAC can remove report-level access enforcement. Resolve the identity, directory-permission, or Kerberos issue indicated by the error instead, particularly where reports expose sensitive data.
Recommended Free Tools
Rank #3
- 【Powerful Load-bearing】12U Network Rack Open Frame is constructed from durable cold rolled steel; Rack shelf supports enhance stability, wall-mounted capacity of 130lbs, the ground-mounted up to 260lbs
- 【Considerate Designs】Open-frame layout, including a top panel adding space, anti-slip shelf stops fixing devices and compatible racks for stack and expansion to meet requirements of home server rack
- 【Complete Accessories】A 12U open frame server rack, two ventilated shelves, four shelf stops, four velcro straps and a set of equipment mounting screws
- 【Versatile Application】Ideal for space-efficient multi-device setups in warehouses, retail, classrooms, offices and more; Excellent choices as AV Rack/IT Rack
- 【Effortless Setup】 Network Rack includes hardware, a comprehensive manual, mounting hole drilling template and an online assembly video to simplify setup
A different SSRS message—“That assembly does not allow partially trusted callers”—is discussed in a separate Microsoft Q&A thread opened January 31, 2025. A community answer reports that removing and re-adding the Reporting Services Point helped in that person’s environment. That anecdotal remedy does not establish a fix for the UserTokenSIDs logon/password error.
Quick Recap
Best Value
- Standard 1U Height: Get more space with our 1U server rack shelf—it comes in a set of 2! Perfect for 19-inch 4-post server racks, it's ideal for stacking routers, switches, firewalls, and other network gear. Easy storage and a neat setup in one simple solution!
- Heavy-Duty Construction: Crafted from premium Q235 carbon steel with a robust 0.06" (1.5 mm) thickness, our server rack shelf can handle up to 50 lbs (22.68 kg) with ease. Say goodbye to wobbles and tilts—perfect for keeping everything in its place!
- Optimal Ventilation: Featuring a perforated bottom design, our network rack shelf effectively reduces equipment temperature, ensuring stable operation and lowering the risk of malfunctions. Keep your gear running smoothly for longer-lasting, reliable performance.
- Flexible Partitioning: With each shelf offering a depth of 10 inches (254 mm), our rack mount shelf helps you organize and optimize your rack space efficiently. Keep your equipment neatly separated to reduce clutter and minimize interference or collisions.
- Installation Made Easy: Comes with all the screws and nuts you need—just grab a Phillips screwdriver and you're all set! Installation is a breeze, and you'll be up and running in no time. Enjoy a more efficient, streamlined setup!
Rank #4
- UNIVERSAL 19'' FIT: This 2U vented server rack mount shelf is designed to fit virtually any 19in server rack and can accommodate an internal depth of 16in (41cm) for your data, IT, networking, or other non-rack mount equipment
- MAXIMIZE VENTILIATION: The vented shelf plate on the cantilever rack shelf ensures consistent airflow to effectively dissipate heat on servers; it also works great to keep your computer and AV equipment cool in your home, studio, or office space
- HEAVY-DUTY & DURABLE DESIGN: Constructed with SPCC commercial cold-rolled steel, the sturdy front mounted cabinet shelf ensures long term durability and supports a total weight of 50lbs/23kg making it the perfect rack shelf solution for any environment
- VERSATILE FUNCTIONALITY: At 16in deep, this fixed rack mount shelf is designed to work with any 19in cabinet or equipment rack. It provides additional storage space for mission critical hardware, and can even store your tools or audio / video accessories
- INDUSTRY-LEADING SUPPORT: This TAA compliant 2U vented server rack mount shelf is backed for life, including free lifetime 24/5 technical assistance
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

