Troubleshooting "rc: 87 - The parameter is incorrect" for Active Directory Terminal Services Attributes - Identity Manager
search cancel

Troubleshooting "rc: 87 - The parameter is incorrect" for Active Directory Terminal Services Attributes - Identity Manager

book

Article ID: 257684

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

This article provides troubleshooting steps for resolving the "Unable to set Terminal Services error" when modifying Active Directory attributes. The specific error returned is "rc: 87 - The parameter is incorrect."

Environment

Identity Manager 14.5

Cause

This error is typically triggered by one of the following factors:

  • Insufficient Permissions: The service account configured in Identity Manager lacks the necessary delegation or administrative rights on the Active Directory object.
  • Network Access Restrictions: Security policies on the network or the Active Directory host are restricting the Connector Server from executing remote Security Account Manager (SAM) calls, a requirement for managing these specific attributes.

Resolution

1. Verify Service Account Permissions

To eliminate permission-based issues as the root cause:

  1. Temporarily grant the Identity Manager service account "Domain Admin" privileges.
  2. Attempt to modify the Terminal Services attribute again.
  3. If the modification succeeds, refine the service account permissions to the minimum necessary level for your specific environment.
  4. If the modification fails even with "Domain Admin" privileges, proceed to investigate network restrictions.

2. Local vs. Remote Testing

Testing locally can help isolate the issue:

  1. Install "Active Directory Users and Computers" (ADUC) tools on both the Active Directory domain controller and the Connector Server.
  2. Test the attribute modification from both locations using the service account.
  3. If modifications succeed locally but fail remotely, confirm that network policies allow remote SAM calls.

3. Review Network Security Policies

The ability to manage these attributes is often controlled by Group Policy Objects (GPOs) that restrict remote access to SAM.

  1. Verify the "Network access: Restrict clients allowed to make remote SAM calls" policy on the domain controllers.
  2. For detailed configuration guidance on managing these restrictions, refer to the official Microsoft documentation on Remote SAM Call restrictions.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.