"PAM-LDAP-0018: Error Adding user CN= ... PAM-CMN-0234: User add failed" trying to add user to PAM group from AD
search cancel

"PAM-LDAP-0018: Error Adding user CN= ... PAM-CMN-0234: User add failed" trying to add user to PAM group from AD

book

Article ID: 282472

calendar_today

Updated On: 04-23-2024

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Refreshing LDAP group failed with the following error for certain user.

PAM-LDAP-0018: Error Adding user CN= ... PAM-CMN-0234: User add failed

Environment

Release: PAM 4.1.x

Resolution

We found the email assigned to the AD user is not in correct format in AD side. After fixing the email data or removing it, re-refreshing the LDAP group resolves the problem.