There are two domains in our corp - in headquarter and in branch office. There is the SFB-server in headquarter domain. SFB-server "knows" only headquarter domain users.
We had created accounts for branch office users in headquarter domain.
When a branchdomain\user in branch office runs client sfb 2016, sfb doesn't connect right away. Then user inputs sip-name, headquarter\username and password in sfb-client interface. And sfb-client sign in. This is not convenient but it's OK.
Several branch office users can't sign in sfb. In sfb-client log I see
403 Forbidden
...
ms-diagnostics: 4004;reason="Credentials provided are not authorized to act as specified from URI";AuthenticatedIdentity="BRANCH\nonEnglishUserName";source="Lync-Srv02.msk.headquarter.local"
ms-diagnostics-public: 4004;reason="Credentials provided are not authorized to act as specified from URI";AuthenticatedIdentity="BRANCH\nonEnglishUserName"
...
IP_MESSAGE::ConstructDiagnosticsInfo Parsing failed for header: 80070459 - skipping header 4004...
This known problem for SFB - non-english symbols in the userlogonname.
But why sfb-client using name of current windows user if I input other username in sfb-client interface ?
Only several users have this problem (from approx. 30 users). Most of branch office users connect in sfb successfully. All 30 branch office users have non-English userlogonnames. And I can't find difference in user or computer configurations.

