< All Topics
Print

Troubleshooting

Trouble Connecting to Untrusted Domains

 If you are having problems connecting to Untrusted Domains, please confirm:

  1. DNS connectivity between your Trusted and Untrusted Domains
  2. UPA has access to SYSVOL on the Untrusted Domains

On the machine where UPA has been installed, the Hardened UNC Paths need to be configured for \\<UntrustedDomainName>\SYSVOL with RequireMutualAuthentication=0, RequireIntegrity=0, RequirePrivacy=0. 

Option 1 – Using Local Group Policy Editor
  1. On the machine where UPA is installed, run gpedit.msc.
  2. Navigate to:
    Computer Configuration → Administrative Templates → Network → Network Provider → Hardened UNC Paths
  3. Open Hardened UNC Paths, set the policy to Enabled, click Show, and add:
    • Value name: \\<UntrustedDomainName>\SYSVOL
    • Value: RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0
  4. Apply and close the editor.
Option 2 – Using Group Policy Management Console (GPMC)
  1. Open Group Policy Management Console.
  2. Navigate to an existing GPO or create a new one.
  3. Go to: Computer Configuration → Administrative Templates → Network → Network Provider.
  4. Locate and open Hardened UNC Paths.
  5. Set the policy to Enabled.
  6. Click Show next to the UNC paths field.
  7. Add a new entry:
    • Value name: \\<UntrustedDomainName>\SYSVOL
    • Value: RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0
  8. Apply and close the editor.
Alternative: Direct Registry Configuration

For direct registry modification:

  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths
  • Value Name: \\<UntrustedDomainName>\SYSVOL
  • Type: REG_SZ
  • Data: RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0
Verification
  1. Run gpupdate /force on the machine where UPA is installed.
  2. Confirm the registry entry exists at the specified path.
  3. Run gpresult /r to verify that the policy is applied.
In This Article