Active Directory (AD) account provisioning fails in CA Identity Manager when multiple AD roles are applied simultaneously via a TEWS call. Because TEWS cannot dictate role application order, group roles may apply before the primary AD role. This results in accounts being created in the "lost and found" Organizational Unit (OU) rather than the intended destination, triggering a duplicate account error when the primary role subsequently attempts to move the user.
Product: CA Identity Manager, CA Identity Governance, CA Identity Portal
The error occurs when multiple Active Directory roles are applied simultaneously via a Task Execution Web Service (TEWS) call.
To ensure accounts are created in the correct OU and avoid duplicate name conflicts, split the role application into two sequential calls: