# Active Directory Provisioning issue

**URL:** <https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, provisioning\
**Created:** [April 16, 2024, 5:12am UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685 "2024-04-16T05:12:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![niket345](https://avatars.discourse-cdn.com/v4/letter/n/ba8739/32.png) [@niket345](https://developer.sailpoint.com/discuss/u/niket345)\
**Post date:** [April 16, 2024, 5:12am UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/1 "2024-04-16T05:12:42Z")

</div>

### Which IIQ version are you inquiring about?

Version 8.4

### Share all details related to your problem, including any error messages you may have received.

Hello Experts,

We are working on AD provision from IIQ and getting below error. Can you please help us to fix this issue.

Errors: Exception occurred while executing the RPCRequest: Errors returned from IQService. Error occurred while enabling the account cn=C327xxxx,OU=xxxx,OU=xxxx,OU=xxxx-QA,DC=xyz,DC=xxxx,DC=comThe server is unwilling to process the request. The server is unwilling to process the request. 0000052D: SvcErr: DSID-031A124C, problem 5003 (WILL\_NOT\_PERFORM), data 0 0000052D: SvcErr: DSID-031A124C, problem 5003 (WILL\_NOT\_PERFORM), data 0 . HRESULT 0x80072035

Thanks

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [April 16, 2024, 5:25am UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/2 "2024-04-16T05:25:59Z")

</div>

Forst thing to be checked if the account in AD has a password set - you won’t be able to enable AD account without password.

---

<div class="post-metadata">

**Author:** ![niket345](https://avatars.discourse-cdn.com/v4/letter/n/ba8739/32.png) [@niket345](https://developer.sailpoint.com/discuss/u/niket345)\
**Post date:** [April 16, 2024, 5:50am UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/3 "2024-04-16T05:50:47Z")

</div>

We are creating the account. we are not enabling it.

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [April 16, 2024, 5:52am UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/4 "2024-04-16T05:52:21Z")

</div>

Then check if password you are setting complies with required AD password complexity.

---

<div class="post-metadata">

**Author:** ![VinodC](https://avatars.discourse-cdn.com/v4/letter/v/a183cd/32.png) [@VinodC](https://developer.sailpoint.com/discuss/u/VinodC)\
**Post date:** [April 16, 2024, 6:56am UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/5 "2024-04-16T06:56:12Z")

</div>

> [@niket345](#):
>
> o

Hi @niket345 ,

Active Directory rejects the account creation request if the password does not meet the configured policy.

I would recommend you check with the Active Directory admin for password policies and meet those then it will work.

---

<div class="post-metadata">

**Author:** ![Muhammad\_Mustafa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/muhammad_mustafa/32/27611_2.png) [@Muhammad\_Mustafa](https://developer.sailpoint.com/discuss/u/Muhammad_Mustafa)\
**Post date:** [April 16, 2024, 8:47pm UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/6 "2024-04-16T20:47:23Z")

</div>

The error is not caused by IIQ, but comes directly from Active Directory. This error may be returned by Active Directory by any one of these problems:

- An attempt to violate a password policy, such as history, password length, blank password, etc.
- An attempt to set a value for an attribute that does not exist
- An attempt to set an incorrect value for an attribute (the value does not adhere to the attribute’s syntax).
- Any other operation that the Active Directory server will not allow.

Ensure that the operation is allowed by Active Directory: passwords should comply with password policy; attributes must exist; attribute values must adhere to the attribute’s syntax. Also check network metrics for anomalies and check network security appliances for closed connections.

> **[Error message: "The server is unwilling to process the request"](https://community.sailpoint.com/t5/IdentityIQ-Wiki/Error-message-quot-The-server-is-unwilling-to-process-the/ta-p/73156)**
>
>   Product All IdentityIQ product versions can show this error since the error comes from Active Directory.   Environment Active Directory   Error You may find one or more of the below in the logs:   "Error occurred while setting...

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [June 15, 2024, 8:47pm UTC](https://developer.sailpoint.com/discuss/t/active-directory-provisioning-issue/50685/7 "2024-06-15T20:47:25Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
