For the newly created users, role sync from provisioning manager is failing.
Errors from the provisioning server logs:
FAILURE: Child Add (eTADSAccountName=Test01)
Retrieving common BLS Connectivity Configuration
rc: 0x0010 (No such attribute)
msg: :ETA_E_0004<AAC>, Active Dir. Account 'Test01' on 'TestEndpoint' creation failed: Connector Server Add failed: code 16 (NO_SUCH_ATTRIBUTE): failed to add entry eTADSAccountName=Test01,eTADSOrgUnitName=Test,eTADSOrgUnitName=Accounts,eTADSDirectoryName=TestEndpoint,eTNamespaceName=ActiveDirectory,dc=im,dc=etasa: JCS@test01: JNDI: [LDAP: error code 16 - Password does not meet installation minimum of 14 characters]: failed to add eTADSAccountName=Test01,eTADSOrgUnitName=Test,eTADSOrgUnitName=Accounts,eTADSDirectoryName=TestEndpoint,eTNamespaceName=ActiveDirectory,dc=im,dc=etasa (ldaps://xx.x.xx.xx:20411)
Release : 14.5.1
Component : CA Identity Suite Virtual Appliance
Temporary password generated for the newly created users are less than 14 characters.
We reset the password to more than 14 characters for the user, the account was created properly on the endpoint.
After that we tried to synchronize the user with role from provisioning manager and it was successful.