PAM-CM-0572 When Trying to Add AD Target Account in 4.2.1 PAM
search cancel

PAM-CM-0572 When Trying to Add AD Target Account in 4.2.1 PAM

book

Article ID: 393598

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

A new Active Directory target account is being added to PAM, but the following error occurs when trying to save it.

PAM-CM-0572: An error occurred; if this problem persists then please ask your Administrator to investigate.

Environment

Privileged Access Manager 4.2.1 with Active Directory target accounts

Cause

The PAM-CM-0572 is a generic error message which has a number of causes. For this scenario, the issue was caused by a bad password for the AD account. In the Tomcat logs, the following error was seen during the time the issue happened. The 52e LDAP error means the username or password was incorrect.

2025-03-26T20:07:02.907+0000 SEVERE [com.cloakware.cspm.server.plugin.targetmanager.WindowsDomainServiceTargetManager] com.cloakware.cspm.server.plugin.targetmanager.CreateLDAPContextAction.performCreateLdapContext Error creating LDAP Context: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090510, comment: AcceptSecurityContext error, data 52e, v4563]

Resolution

Update the account in AD and set its password to match the one being stored in PAM. Once the username and password match, the account will save successfully.