There has been an anomaly noted the last few days where users recently added to active directory are not able to authenticate through the LDAP user directories configured in our Jira instance. For context, we upgraded our LDAP user directories to use SSL last October and have noted no issues. For further context, our user directories were initially configured with two user directories per zone with one (I assume) designated for authentication and the other set to synchronize at an interval to (again, I assume) keep whatever caches up-to-date with any LDAP changes.
The user directory order goes like:
Zone 1
Zone 2
...
Zone N
Zone 1(sync)
Zone 2(sync)
...
Zone N(sync)
I disabled the directories that sync nearly two weeks ago in order to cut down on the volume of requests to the LDAP server with no interruption noted with users logging in.
However, yesterday a robot account was created in our AD for use in some automations, and we attempted to add this new account to Jira. When trying to login with this account, I get the message "Sorry, your username and password are incorrect - please try again." I read that I may want to change the password of this account in active directory and try again, which I did, with no change in this behavior. The user has application access via group permissions. This user can be logged into other systems using its AD credentials.
The `atlassian-jira-security.log` displays these errors:
2024-01-10 09:06:35,313 https-jsse-nio-443-exec-25 anonymous 546x145341x3 bxkryf <some.ip.address> /login.jsp login : 'username' tried to login but they do not have USE permission or weren't found. Deleting remember me cookie.
2024-01-10 09:06:35,313 https-jsse-nio-443-exec-25 anonymous 546x145341x3 bxkryf <some.ip.address> /login.jsp The user 'username' has FAILED authentication. Failure count equals 5
2024-01-10 09:06:35,313 https-jsse-nio-443-exec-25 anonymous 546x145341x3 bxkryf <some.ip.address> /login.jsp login.jsp called with lastLoginResult : com.atlassian.jira.bc.security.login.LoginResultImpl@1111e315[reason=AUTHENTICATED_FAILED,loginInfo=com.atlassian.jira.bc.security.login.LoginInfoImpl@42277812[lastLoginTime=<null>,previousLoginTime=<null>,loginCount=<null>,currentFailedLoginCount=5,totalFailedLoginCount=5,lastFailedLoginTime=1704895595313,elevatedSecurityCheckRequired=false,maxAuthenticationAttemptsAllowed=9223372036854775807],userName=username,deniedReasons=[]]
I went and looked at the user directory configuration for the zone that I *know* this user exists on a ran a quick test against my credentials:

And then I ran the same quick test against the newly added user:

No error messages or anything, just flatly telling me that the user doesn't exist in the AD server where I *know* both of our accounts live. What could possibly account for this behavior?