This article addresses the error "Password change is not permitted on deleted account," which occurs when Identity Manager attempts to propagate password changes to an account currently in a "Delete Pending" state.
Identity Manager 14.5 & 15
This issue occurs when an endpoint is configured with the "Accounts will enter Delete Pending state" option enabled. When this setting is active:
eTAccountDeletable attribute on the endpoint is set to 0.Because these accounts are effectively suspended, standard operations—such as password synchronization—are restricted.
Determine if the "Delete Pending" behavior aligns with your organization's requirements.
For accounts currently in the "Delete Pending" state, choose one of the following remediation paths:
Option A: Perform a Forced Delete:
eTAccountForcedDeletable to 1).ldapmodify, or etautil to set the eTForcedDelete attribute on the account to 1. This triggers the actual deletion process.Option B: Clear the "Delete Pending" Status:
ldapmodify, or etautil to clear the following attributes from the account object:eTSuspendedDateeTSuspendedTimeeTSuspendedReasonFor further information, see documentation Use Delete Pending - 14.5 or Use Delete Pending - v15 and Troubleshooting Identity Manager Errors (Knowledge Base)
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.