Troubleshooting "Password change is not permitted on deleted account" Errors - Identity Manager
search cancel

Troubleshooting "Password change is not permitted on deleted account" Errors - Identity Manager

book

Article ID: 257599

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

This article addresses the error "Password change is not permitted on deleted account," which occurs when Identity Manager attempts to propagate password changes to an account currently in a "Delete Pending" state.

Environment

Identity Manager 14.5 & 15

Cause

This issue occurs when an endpoint is configured with the "Accounts will enter Delete Pending state" option enabled. When this setting is active:

  • The eTAccountDeletable attribute on the endpoint is set to 0.
  • Accounts are marked as "Delete Pending" instead of being deleted immediately.
  • The Provisioning Server removes all associated account templates and clears multi-valued capability attributes on these accounts.

Because these accounts are effectively suspended, standard operations—such as password synchronization—are restricted.

Resolution

1. Evaluate Endpoint Configuration

Determine if the "Delete Pending" behavior aligns with your organization's requirements.

  • Navigate to the Endpoint Settings tab for the relevant endpoint.
  • Verify the configuration for the "Accounts will enter Delete Pending state" setting. Disable this option if you require immediate account deletion.

2. Managing Existing "Delete Pending" Accounts

For accounts currently in the "Delete Pending" state, choose one of the following remediation paths:

  • Option A: Perform a Forced Delete:

    1. Ensure "Allow forced delete of accounts" is enabled on the Endpoint Settings tab for the endpoint (sets eTAccountForcedDeletable to 1).
    2. Use an LDAP browser, ldapmodify, or etautil to set the eTForcedDelete attribute on the account to 1. This triggers the actual deletion process.
  • Option B: Clear the "Delete Pending" Status:

    1. Use an LDAP browser, ldapmodify, or etautil to clear the following attributes from the account object:
      • eTSuspendedDate
      • eTSuspendedTime
      • eTSuspendedReason
    • Note: Clearing these attributes restores the account to an active status. However, verify if account templates or capability attributes require manual restoration, as these were cleared when the account entered the "Delete Pending" state.

Additional Information

For further information, see documentation Use Delete Pending - 14.5 or Use Delete Pending - v15 and Troubleshooting Identity Manager Errors (Knowledge Base)

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.