# Issues on Provisioning All Attributes to AD

**URL:** <https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [September 21, 2023, 3:46am UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902 "2023-09-21T03:46:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sjoyee](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@sjoyee](https://developer.sailpoint.com/discuss/u/sjoyee)\
**Post date:** [September 21, 2023, 3:46am UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/1 "2023-09-21T03:46:40Z")

</div>

Hi.  
We are having issues to provision all the attributes to Active Directory. The following are the warnings and errors we found from the search API (accountactivities).

> “warnings”: [  
> “Account created but failed to modify : Failed to update attributes for identity “distinguishedName”. The requested operation did not satisfy one or more constraints associated with the class of the object.\n”  
> ]

In the Account Requests, we notice the following warning and error:

> “result”: {  
> “warnings”: [  
> “Account created but failed to modify : Failed to update attributes for identity “distinguishedName”. The requested operation did not satisfy one or more constraints associated with the class of the object.\n”  
> ],  
> “errors”: [  
> “Account created but some attributes are not updated properly.”  
> ],  
> “status”: “committed”  
> },

Please advise. Thank you!

---

<div class="post-metadata">

**Author:** ![RAKGDS](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rakgds/32/2795_2.png) [@RAKGDS](https://developer.sailpoint.com/discuss/u/RAKGDS)\
**Post date:** [September 21, 2023, 5:08am UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/2 "2023-09-21T05:08:21Z")

</div>

Hi Jo,  
Thank you for your post. This errors comes when we are trying to set value which are not permitted at AD side. For eg middleName which is Initials has a limit for the number of characters we can send.

Could you please check on the above ? Also are you populating manager in the AD in the correct format ?

Thanks

---

<div class="post-metadata">

**Author:** ![gauravsajwan1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gauravsajwan1/32/7856_2.png) [@gauravsajwan1](https://developer.sailpoint.com/discuss/u/gauravsajwan1)\
**Post date:** [September 21, 2023, 6:28am UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/3 "2023-09-21T06:28:16Z")

</div>

Hi @sjoyee , I believe the error is related to the character limit for one or more of the AD attributes that you are trying to provision while creating an AD account.

Refer AD documentation: [All Attributes - Win32 apps | Microsoft Learn](https://learn.microsoft.com/en-us/windows/win32/adschema/attributes-all) for character limit information and then compare it with your attribute values that you are sending from IDN to AD for the affected users. I think you will get the answer there.  
Additionally, if you have pre-prod AD access, then you can try manually updating the attribute which you think might be causing the issue just to confirm.

All the best!

---

<div class="post-metadata">

**Author:** ![sjoyee](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@sjoyee](https://developer.sailpoint.com/discuss/u/sjoyee)\
**Post date:** [September 21, 2023, 10:37am UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/4 "2023-09-21T10:37:39Z")

</div>

Hi Rakesh. Thank you for the input! The error is the number of characters passed in the AD attribute to be provisioned. It works when we remove this attribute.

However, this attribute is needed for us to retrieve and put as value in the static field.  
For example, distinguishedName = $abc,$bcd, but $bcd (retrieved from identity attribute) is having exceeding characters. Is there any way for us to filter out $bcd to be provisioned to AD, or other way to create a pattern using a combination of attribute in the plan and identity attribute?

---

<div class="post-metadata">

**Author:** ![sjoyee](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@sjoyee](https://developer.sailpoint.com/discuss/u/sjoyee)\
**Post date:** [September 21, 2023, 12:02pm UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/5 "2023-09-21T12:02:32Z")

</div>

It seems that we found a way for doing this. Everything is working as expected now. Thank you!

[AD After Create/Modify Values - IdentityNow (IDN) / Discussion and Questions - SailPoint Developer Community Forum](https://developer.sailpoint.com/discuss/t/ad-after-create-modify-values/3704)

---

<div class="post-metadata">

**Author:** ![RAKGDS](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/rakgds/32/2795_2.png) [@RAKGDS](https://developer.sailpoint.com/discuss/u/RAKGDS)\
**Post date:** [September 21, 2023, 12:08pm UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/6 "2023-09-21T12:08:05Z")

</div>

Great we also right the below for distinguish name if you want to see the pattern.

{  
“attributes”: {  
“cloudMaxSize”: “100”,  
“cloudMaxUniqueChecks”: “5”,  
“cloudRequired”: “true”  
},  
“isRequired”: false,  
“multi”: false,  
“name”: “distinguishedName”,  
“transform”: {  
“type”: “usernameGenerator”,  
“attributes”: {  
“sourceCheck”: true,  
“patterns”: [  
“CN=$fi$ln,$ou”,  
“CN=$fn$ln,$ou”,  
“CN=$fn$mi$ln,$ou”,  
“CN=$fn$mi$ln${uniqueCounter},$ou”  
],  
“fn”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “firstNameLower”  
}  
},  
“ln”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “lastNameLower”  
}  
},  
“ou”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “ou”  
}  
},  
“fi”: {  
“type”: “substring”,  
“attributes”: {  
“input”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “firstNameLower”  
}  
},  
“begin”: 0,  
“end”: 1  
}  
},  
“mi”: {  
“type”: “substring”,  
“attributes”: {  
“input”: {  
“type”: “identityAttribute”,  
“attributes”: {  
“name”: “middleNameLower”  
}  
},  
“begin”: 0,  
“end”: 1  
}  
}  
}  
}

}

---

<div class="post-metadata">

**Author:** ![sjoyee](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@sjoyee](https://developer.sailpoint.com/discuss/u/sjoyee)\
**Post date:** [September 21, 2023, 12:12pm UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/7 "2023-09-21T12:12:01Z")

</div>

Hi Rakesh,

Noted with this. It is a really useful information for us, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [November 20, 2023, 12:12pm UTC](https://developer.sailpoint.com/discuss/t/issues-on-provisioning-all-attributes-to-ad/17902/8 "2023-11-20T12:12:11Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
