Issue creating msDS-ShadowPrincipal in ESAE/PAM forest

Jordan Mills 2 Reputation points
2021-02-22T17:30:52.157+00:00

We have an ESAE forest with one domain (priv) and a user/resource forest (blue) with several domains (one.blue, two.blue, three.blue). Another domain was added to the user forest (four). Before and after creating the domain four.blue, we were and are able to create msDS-ShadowPrincipal objects for groups in one.blue, two.blue, and three.blue. But we are not able to create msDS-ShadowPrincipal objects for groups in four.blue.

When trying to create a new msDS-ShadowPrincipal object with New-ADObject, the error is "New-ADObject : The requested operation did not satisfy one or more constraints associated with the class of the object". I assumed this was an undocumented constraint based on the trust object in the priv forest. But we are still getting the error even after validating/refreshing the trust.

Is there something I'm missing? The next step is to delete/recreate the trust, but I'd like to avoid doing that.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.