After upgrade to SEPM 14.2.1, we lost the ability to log in to the Management Console with AD authentication. This is a known issue:
https://support.symantec.com/us/en/article.tech251819.html
If you use AD authentication to log in to SEPM, MAKE SURE you have a working local administrator account before you perform the 14.2.1 upgrade. You will not be able to use your AD account on SEPM login page. You will have to be able to log in using a local admin account in order to fix the AD authentication problem:
Admin/Servers/Select management server below Local Site (My Site)/Edit the server properties/Directory Servers tab/Select a Directory Server and click Edit/Enter a FQDN in the "Server IP Address or Name" field - not just the hostname
I found that the IP address of a DC did not work for me, but a FQDN did.
Also, if you are running SEPM in a virtualized environment, create a snapshot of the server before attempting the 14.2.1 upgrade.