Running a vastool create command as an AD user fails with the following:
ERROR: Failed to create user <username>
VAS_ERR_FAILURE: Unspecified failure
Could not set password
Caused by:
VAS_ERR_ACCESS: Access denied
<username>@<domain> does not have permission to set the password for user2@domain. The account may be locked.
Caused by:
KPASSWD_ACCESSDENIED: Access denied
This can be caused when the account that was granted permissions to set password for objects was delegated rights by a domain local security group.
Product Defect #424350
Fix: Upgrade to version 4.1.5.23531 of Authentication Services or above.
Workaround: Set the domain local group to be a universal group.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Termini di utilizzo Privacy Cookie Preference Center