When using an import file to merge a source account with samAccountName to the target account (sjohnson -> stjohnson), it's erroring with "LDAP error 0x44. Already Exists (00002071: UpdErr: DSID-031B0B8D, problem 6005 (ENTRY_EXISTS), data 0"
Target AD account already exists and it's not stamped. Migration session errors out with "conflict by attribute".
To resolve the issue, please make sure to stop all dirsync activity that is using the DSA agent or use a separate DSA to run the migration session. This will make sure that dsa.log file is clear from other activities and will speed up troubleshooting.
Run the migration session and analyze the dsa.log for: which target account has been found by DSA (samAccountName, UPN), when it tried to find a match. Also, write down which DC/GC is set as preferred for the target domain in DSA Properties in Agent Manager.
Using ADUC on the target domain, connect to the DC/GC and clear service attributes used by QMM for stamping. Make sure that matching service attribute on the wrong target object (last 5-6 hexadecimal symbols) is matching the source object's objectGUID attribute (same last 5-6 hexadecimal symbols). Clear both, auxiliary and matching attributes in ADUC and re-run the migration session.
Note: to find what attributes are used as service attributes, go to properties of the domain pair, Object Matching and click on Service Attributes. Select a proper class for the target domain and it'll populate service attributes below. Click Cancel when done.
© ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center