# Error when adding identities to an Active Directory source

**URL:** <https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, accounts, identity-security-cloud\
**Created:** [July 17, 2024, 7:35am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049 "2024-07-17T07:35:28Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [July 17, 2024, 7:35am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/1 "2024-07-17T07:35:28Z")

</div>

I have a problem when adding accounts to an Active Directory source in our demo tenant. When I try to add them it sends the next error:

 ![undefined](https://global.discourse-cdn.com/sailpoint/original/2X/d/d90c128510b07310cef51c4b4bce076840a57849.png)

The weird thing is that it worked for 2 identities (one of them was mine), but It hasn’t worked ever again.

---

<div class="post-metadata">

**Author:** ![dylanfoggan](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/dylanfoggan/32/13658_2.png) [@dylanfoggan](https://developer.sailpoint.com/discuss/u/dylanfoggan)\
**Post date:** [July 17, 2024, 9:09am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/2 "2024-07-17T09:09:13Z")

</div>

Hi @rcgalvez ,

Please share your “Create Account” configuration that was set for the “displayName” attribute.

What could also be useful is providing the account activity available from **Search**

Thanks,

---

<div class="post-metadata">

**Author:** ![neeraj99](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neeraj99/32/14001_2.png) [@neeraj99](https://developer.sailpoint.com/discuss/u/neeraj99)\
**Post date:** [July 17, 2024, 9:34am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/3 "2024-07-17T09:34:15Z")

</div>

DisplayName attribute that you have on Create Profile of Active Directory there’s the issue. If you are using the generator to create the display name then, the format that it is using to generate the Display name was already found in the AD application so it went ahead and generated a new one did this same thing 50 times and then failed to generate. So if you are still needing the generator for DisplayName then check the format.

Secondly, to see what was sent to AD, goto Search, and search for this user.  
Click on account activity, and look for the failed request where AD account creation was failed. Now, check the attribute Display Name, you will see what it tried to sent.

Hope this helps…

---

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [July 17, 2024, 9:51am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/4 "2024-07-17T09:51:50Z")

</div>

Thank you for your answer. We fixed that problem, but we’re still having trouble.

---

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [July 17, 2024, 9:53am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/5 "2024-07-17T09:53:34Z")

</div>

We have this usernamegenerator transform and this is what is creating the problem. We can’t get it to work.

```auto
 {
            "name": "externalEmailAddress",
            "transform": {
                "type": "usernameGenerator",
                "attributes": {
                    "sourceCheck": true,
                    "patterns": [
                        "$inicial_ln"
                    ],
                    "inicial_ln": {
                        "type": "static",
                        "attributes": {
                            "name": "lastname_test"
                        }
                    }
                }
            },

```

---

<div class="post-metadata">

**Author:** ![neeraj99](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neeraj99/32/14001_2.png) [@neeraj99](https://developer.sailpoint.com/discuss/u/neeraj99)\
**Post date:** [July 17, 2024, 12:07pm UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/6 "2024-07-17T12:07:12Z")

</div>

Okay, so i see that in patterns you have defined only one pattern and no counter to create a unique new value, which means that whatever you are sending from **$inicial\_ln** it will always take that and because everytime it is checking the same value it is failing to create a new unique value.  
Under patterns add another pattern something like this

```auto
"patterns":[
"$inicial_ln",
"$inicial_ln${uniqueCounter}"
]

```

So eventually if the first pattern is not unique, it will move to second and create a unique pattern  
**Ex:** if the inicial\_ln is coming as N, and same is present in AD, then 2nd pattern template will be followed and N1 will be tried if it is also present, then next counter will be added i.e N2, and continued until get a unique value.

You can add other patterns as well attaching the document for reference: [Username Generator | SailPoint Developer Community](https://developer.sailpoint.com/docs/extensibility/transforms/operations/username-generator/)

Hope this helps…

---

<div class="post-metadata">

**Author:** ![rcgalvez](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@rcgalvez](https://developer.sailpoint.com/discuss/u/rcgalvez)\
**Post date:** [July 18, 2024, 5:41am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/7 "2024-07-18T05:41:22Z")

</div>

We already tried that and still doesn’t work. We even tried with a static value and still gives out an error when adding the identity to AD.

---

<div class="post-metadata">

**Author:** ![neeraj99](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neeraj99/32/14001_2.png) [@neeraj99](https://developer.sailpoint.com/discuss/u/neeraj99)\
**Post date:** [July 18, 2024, 5:48am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/8 "2024-07-18T05:48:15Z")

</div>

Can you paste the screenshot of the error in here,  
You can get it from Search-\>Search the test user-\>Account Activity-\> Failed account activity with error.

That can help to deduce the issue further.

---

<div class="post-metadata">

**Author:** ![RAKGDS](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rakgds/32/2795_2.png) [@RAKGDS](https://developer.sailpoint.com/discuss/u/RAKGDS)\
**Post date:** [July 18, 2024, 5:48am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/9 "2024-07-18T05:48:44Z")

</div>

Hi Raul,  
I am not sure if you can use a static value for the transform in a pattern.  
Can you please use any identity attribute as a value ? Below is example for DN calculation transform.

{  
“attributes”: {  
“cloudMaxSize”: “100”,  
“cloudMaxUniqueChecks”: “5”,  
“cloudRequired”: “true”  
},  
“isRequired”: false,  
“multi”: false,  
“name”: “distinguishedName”,  
“transform”: {  
“type”: “usernameGenerator”,  
“attributes”: {  
“sourceCheck”: true,  
“patterns”: [  
“CN=$fi$ln,$ou”,  
“CN=$fn$ln,$ou”,  
“CN=$fn$mi$ln,$ou”,  
“CN=$fn$mi$ln${uniqueCounter},$ou”  
],  
“fn”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “firstNameLower”  
}  
},  
“ln”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “lastNameLower”  
}  
},  
“ou”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “ou”  
}  
},  
“fi”: {  
“type”: “substring”,  
“attributes”: {  
“input”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “firstNameLower”  
}  
},  
“begin”: 0,  
“end”: 1  
}  
},  
“mi”: {  
“type”: “substring”,  
“attributes”: {  
“input”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “middleNameLower”  
}  
},  
“begin”: 0,  
“end”: 1  
}  
}  
}  
}

}

---

<div class="post-metadata">

**Author:** ![neeraj99](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neeraj99/32/14001_2.png) [@neeraj99](https://developer.sailpoint.com/discuss/u/neeraj99)\
**Post date:** [July 18, 2024, 5:51am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/10 "2024-07-18T05:51:46Z")

</div>

@rauls hey just got why this could be happening.

So i see the transform that you have pasted in the chat, is of type static but the value is not given

```auto
{
            "name": "externalEmailAddress",
            "transform": {
                "type": "usernameGenerator",
                "attributes": {
                    "sourceCheck": true,
                    "patterns": [
                        "$inicial_ln"
                    ],
                    "inicial_ln": {
                        "type": "static", 
                        "attributes": {
                            //"name": "lastname_test" //if you want to use identity attribute then will have to change the type to identityAttribute
                            "value":"N" //if you are using static then value should be the key
                        }
                    }
                }
            },

```

Can you try this out and letme know if the issue still exists…

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 16, 2024, 5:51am UTC](https://developer.sailpoint.com/discuss/t/error-when-adding-identities-to-an-active-directory-source/73049/11 "2024-09-16T05:51:53Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
