Registration failed due to duplicate AD LDS directory partition DN error when trying to add a second AD LDS instance from a different server.
This issue occurs when two or more AD LDS instances being registered in Active Roles share the same distinguished name (DN) for their directory partitions (for example, DN=Company
).
Active Roles requires each managed directory partition to have a unique DN to correctly identify and manage directory objects. When duplicate DNs are detected, Active Roles cannot differentiate between objects across instances, and therefore registration fails.
WORKAROUND
None.
This behavior is by design. The uniqueness check ensures consistency and prevents potential conflicts or data integrity issues within Active Roles.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center