Privileged Access Management (PAM) admin is attempting to update a user with the "Global Administrator" role. They also defined a "Credential Manager Group" as well. However when they go to save the updated user, they get the error:
PAM-CMN-0155: User <username> was not updated.
In the session logs, the following error message also was seen:
PAM-CMN-2261: Password Authority failure to try to activate user <username>. Message: PAM-CM-0873: Invalid user group ID. User group ID 1005 does not exist.
Group ID of 1005 is our Out of the Box Credential Manager Group called "Secrets Management Users".
This group was not created
Created the Secrets Management Users group in:
PAM UI >> Credentials >> Manage Credential Groups >> Credential Groups.
Secrets Management Users
with the SecretsManagementUser role (which was created), which resolved the issue.