"The specified directory service attribute or value already exists" modify user on Server 2019

Imre László 1 Reputation point
2023-01-04T19:49:22.843+00:00

Dear community!

Software: Windows Server 2019 Essentials as domain controller. When I want to change any data of any user in a given OU, I get this error message:

"The specified directory service attribute or value already exists"

I also tried changing the user from PowerShell, the problem is the same. I am past the first 30 hits of our friend Google. I retrieved the data of each user with PowerShell, I checked if there was a unique conflict somewhere, there was none. What else can I do, how would you continue troubleshooting? I'd like to add another PC to "Log on to..." field. My PowerShell commands are:

$Workstations = (Get-ADUser my.user.name -Properties LogonWorkstations).LogonWorkstations
$Workstations += ",NEW-NAME"
Set-ADUser my.user.name -LogonWorkstations $Workstations

Windows for business Windows Client for IT Pros Directory services Active Directory
Windows for business Windows Server User experience PowerShell
Windows for business Windows Server User experience Other
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Imre László 1 Reputation point
    2023-01-04T19:59:50.597+00:00

    Additional info: there are 4 users in this OU. The names, for sample:

    familyname.user1
    familyname.user2
    familyname.user3
    different.name

    The first 3, when "familyname" are identical, I cannot edit the user.
    The fourth user with totally different name: I can edit this user.
    The first 3 users have mailbox, the fourth not, if this matters.

    0 comments No comments

  2. Imre László 1 Reputation point
    2023-01-04T20:14:05.017+00:00

    Here is one of the problematic users (name info replaced with word "sample" and "name", domain with "sampledomain.tld"):

    AccountExpirationDate :
    accountExpires : 9223372036854775807
    AccountLockoutTime :
    AccountNotDelegated : False
    AllowReversiblePasswordEncryption : False
    AuthenticationPolicy : {}
    AuthenticationPolicySilo : {}
    BadLogonCount : 0
    badPasswordTime : 133173208164148764
    badPwdCount : 0
    CannotChangePassword : True
    CanonicalName : sampledomain.tld/JM-DEFAULT/Sample Name
    Certificates : {}
    City :
    CN : Sample Name
    codePage : 0
    Company :
    CompoundIdentitySupported : {}
    Country :
    countryCode : 0
    Created : 2022. 05. 04. 8:23:22
    createTimeStamp : 2022. 05. 04. 8:23:22
    Deleted :
    Department :
    Description :
    DisplayName : Sample Name
    DistinguishedName : CN=Sample Name,OU=JM-DEFAULT,DC=samplemerleg,DC=tld
    Division :
    DoesNotRequirePreAuth : False
    dSCorePropagationData : {2023. 01. 04. 16:01:11, 2023. 01. 04. 16:00:49, 2022. 05. 04. 8:59:49, 2022. 05. 04. 8:23:22...}
    EmailAddress : ******@sampledomain.tld
    EmployeeID :
    EmployeeNumber :
    Enabled : True
    Fax :
    fetchmailAccount : {Base64EncodedDataHere}
    gidNumber : 2513
    GivenName : Name
    HomeDirectory :
    HomedirRequired : False
    HomeDrive :
    HomePage :
    HomePhone :
    Initials :
    instanceType : 4
    isDeleted :
    KerberosEncryptionType : {}
    LastBadPasswordAttempt : 2023. 01. 04. 16:46:56
    LastKnownParent :
    lastLogoff : 0
    lastLogon : 133173211534987858
    LastLogonDate : 2022. 12. 27. 9:11:53
    lastLogonTimestamp : 133166023134131210
    LockedOut : False
    logonCount : 89
    LogonWorkstations : DESKTOP-TKAHDGT,JM-ASUS-FA65
    mail : ******@sampledomain.tld
    mailbox : sampledomain.tld/sample.name/
    mailHomeDirectory : {/var/vmail/}
    mailquota : 10240
    Manager :
    MemberOf : {CN=JM_USERS,CN=Users,DC=sampledomain,DC=tld}
    MNSLogonAccount : False
    MobilePhone :
    Modified : 2023. 01. 04. 16:01:11
    modifyTimeStamp : 2023. 01. 04. 16:01:11
    msDS-User-Account-Control-Computed : 0
    Name : Sample Name
    nTSecurityDescriptor : System.DirectoryServices.ActiveDirectorySecurity
    ObjectCategory : CN=Person,CN=Schema,CN=Configuration,DC=sampledomain,DC=tld
    ObjectClass : user
    ObjectGUID : 0cd9a306-aad4-4634-a599-12d8e75ca271
    objectSid : S-1-5-21-121529692-3925751680-3766135194-1116
    Office :
    OfficePhone :
    Organization :
    OtherName :
    PasswordExpired : False
    PasswordLastSet : 2022. 05. 04. 8:23:22
    PasswordNeverExpires : True
    PasswordNotRequired : False
    POBox :
    PostalCode :
    PrimaryGroup : CN=Domain Users,CN=Users,DC=sampledomain,DC=tld
    primaryGroupID : 513
    PrincipalsAllowedToDelegateToAccount : {}
    ProfilePath :
    ProtectedFromAccidentalDeletion : False
    pwdLastSet : 132961190024300816
    quota : 10240
    SamAccountName : sample.user
    sAMAccountType : 805306368
    ScriptPath :
    sDRightsEffective : 15
    ServicePrincipalNames : {}
    SID : S-1-5-21-121529692-3925751680-3766135194-1116
    SIDHistory : {}
    SmartcardLogonRequired : False
    sn : Sample
    State :
    StreetAddress :
    Surname : Sample
    Title :
    TrustedForDelegation : False
    TrustedToAuthForDelegation : False
    uidNumber : 65542
    UseDESKeyOnly : False
    userAccountControl : 66048
    userCertificate : {}
    userMaildirSize : 0
    UserPrincipalName : ******@sampledomain.tld
    userWorkstations : DESKTOP-TKAHDGT,JM-ASUS-FA65
    uSNChanged : 3178619
    uSNCreated : 2509778
    whenChanged : 2023. 01. 04. 16:01:11
    whenCreated : 2022. 05. 04. 8:23:22

    0 comments No comments

  3. Rich Matheisen 47,901 Reputation points
    2023-01-04T22:39:29.913+00:00

    You said that the 1st three users have a mailbox? Where?

    Windows Server 2019 Essentials limitations
    Only works with Retail licenses of Office;
    It is not possible to work remotely;
    A max. of 25 users;
    Cannot work with SQL Server, Exchange Server and Sharepoint Server.

    EDIT: Never mind. the mail system is *nix:

    mailbox : sampledomain.tld/sample.name/  
    mailHomeDirectory : {/var/vmail/}  
    

  4. Rich Matheisen 47,901 Reputation points
    2023-01-05T03:04:53.45+00:00

    The list of properties you provided for one of the problematic users includes userWorkstations : DESKTOP-TKAHDGT,JM-ASUS-FA65. So you were, at one point, able to modify that user. What has changed since then?

    Can you modify any properties of that user? Can you do so with ADUC and PowerShell, or only with one and not the other?


  5. Rich Matheisen 47,901 Reputation points
    2023-01-05T16:07:40.923+00:00

    You realize that the Server 2019 Essentials can be the ONLY domain controller, don't you? It must run ALL FSMO roles.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.