AD domain no longer able to create accounts; Error being - UNABLE TO PERFORM. Attribute: unicodePwd ===> Values ...(suppressed)... 
search cancel

AD domain no longer able to create accounts; Error being - UNABLE TO PERFORM. Attribute: unicodePwd ===> Values ...(suppressed)... 

book

Article ID: 199241

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Identity Suite

Issue/Introduction

Oneof the AD domains was no longer able to create accounts; Error: UNABLE TO PERFORM.

Account creation at AD Endpoint failed with "Unable to set Password - Reason: Unwilling To Perform" error

We found the following error in ADS log

15:46:18 - TID:0x359c Server: TESTXXXXADDS001.TESTADXXX.COM : Credentials: [SVC_CAIDM]
ADS->MODIFY: DN: [CN=Test User,OU=USERS,OU=State,OU=001,DC=TESTADXXX,DC=com] rc=53 (elapsed: 48 ms)
 [REP] Attribute: unicodePwd ===> Values ...(suppressed)... 

Resolution

The problem was due to configuration in a third party (Hitachi password manager) utility. The customer resolved the configuration issue via the third party application.