All versions of Centrify DirectControl on all platformsQuestion:
How to prove that a UNIX user was authenticated by AD?Answer:
If we want to see adclient authenticate user with Active Directory's DC in action, then addebug is the only way. Turn '/usr/share/centrifydc/bin/addebug on', have AD login, then the log will show adclient authenticate with AD(Please refer this KB-0062 https://centrify.force.com/support/Article?id=ka080000000PiIE
for more details on capturing debug logs).
To prove that that the users are coming from AD,we could get a cache dump then the section uid.idx/uname.idx will show user's AD dn. Cache dump can be obtained by root runs
/usr/share/centrifydc/bin/adcache -L -o /tmp/adcache.txt.