Error adding SIDs during SIDHistory migration for 'CN=username,OU=SomeOU,DC=ABC,DC=domain,DC=com,DC=ABC' (SQL ID: 5555555). Inappropriate authentication
"Write: Directory Operation Error (ConstraintViolation): 000021C8: AtrErr: DSID-03200E93, #1:
0: 000021C8: DSID-03200E93, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 90290 (userPrincipalName)
or
Failed to add objectSid of ...
The domain is not allowing access while specifying credentials by UPN for the service account.
This happens when the Domain Suffixes don't match the service account UPN Suffix.
Possible changes made in a recent Microsoft Windows update ( week of 4/5/2022)
Other possible causes can be:
- RC4 Kerberos authentication method disabled.
- Mismatch in the authentication method (agent server and DC's).
1. Uninstall the Synchronization agent.
2. Delete the Dirsync Agent registry entry, located here:
P365 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Binary Tree\P365Agent
ODM Location: ODM Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Quest\On Demand Migration For Active Directory\ODMAD_DS
3. Reinstalling the Synchronization Agent, and specify Domain\Service_Account instead of UPN for the "Username" on the "SID History Migration" screen. Make sure to enter the source account credentials.
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center