Enterprise app provision error

Alok Singh 1 Reputation point
2022-07-29T09:50:20.23+00:00

When creating user from Workday to Active Directory, getting below error in provision audit logs. Please help me on this issue.

Failed to update Worker 'xxx' in On Premises Active Directory; Error: UnwillingToPerform-SvcErr: The server cannot handle directory requests.. The directory service cannot perform the requested operation on the RDN attribute of an object. \nError Details: Problem 5003 - WILL_NOT_PERFORM. This operation was retried 3 times. It will be retried again after this date: 2022-07-30T07:26:46.3710536Z UTC

More details- Newly created user is always sync with old user which is already exist in AD.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jess Astorga 111 Reputation points Microsoft Employee
    2022-07-29T15:29:48.133+00:00

    Hello Alok,

    Thank you for the details provided, the messages "UnwillingToPerform-SvcErr: The server cannot handle directory requests" and "Problem 5003 - WILL_NOT_PERFORM messages" indicate that there's an operation being sent to Active Directory that is invalid.

    Updating RDN attribute is currently unsupported and will cause the error message you've experienced, the resolution for this issue is to either remove the attribute from the mappings or apply the mapping "Only during object creation".

    If you would like to take a deeper look at the behavior and discuss the resolution, I would recommend creating a support case and include the application ID and the same sample provided on this forum.

    Thanks!

    -Jessie

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.