When attempting to modify an account password on a managed endpoint in CA Identity Manager, the operation fails if the system is configured to use the administrator's credentials but the corresponding administrator account does not exist on that specific endpoint.
Identity Manager 14.x
This issue occurs when the Use logged in Administrator's Credentials setting is enabled in the Directory Settings tab of the endpoint properties.
When this setting is active, any administrative action (such as a password reset) performed via the Admin UI must authenticate against the endpoint using the credentials of the currently logged-in Global User. For example, if you are logged in as etaadmin and attempt to change a user's password, the system tries to use an etaadmin account on the endpoint to authorize the change. If that account does not exist on the endpoint, the ETA_E_0008 error is returned.
Follow one of the two methods below to resolve the authentication error:
Method 1: Disable Administrator Credential Inheritance
Method 2: Create the Administrative Account on the Endpoint
etaadmin) that matches the Global User ID exactly.