Attempting to log into the Active Roles Web Interface fails with the error message: An error has occurred.
The Secure Token Service logs show the following error:
Message: Object reference not set to an instance of an object.
Exception: System.NullReferenceException
Stack:
at RSts.Sts.LdapCommon.Util.GetAttribute[T](SearchResultEntry sre, String name)
at RSts.ActiveDirectoryProvider.Context.PopulateMaxPwdAndLockoutDurationCache(String path, Boolean isFgpp)
at RSts.ActiveDirectoryProvider.Context.GetMaxPwdAge(String path, Boolean isFgpp)
at RSts.ActiveDirectoryProvider.User.get_TimeUntilPasswordExpires()
at Rsts.CustomClaim.GenerateClaims(IUser user, AuthenticationMethod authMethod, String password, String relyingPartyRealmID)
at Rsts.WebRoot.UserLogin.LoginController.GetClaimsPrincipal()
at Rsts.WebRoot.UserLogin.LoginController.ProcessWSFedSignIn(Uri overrideUri)
at Rsts.WebRoot.UserLogin.LoginController.FinishFederatedLogin(Boolean skipChangePasswordCheck)
at Rsts.WebRoot.UserLogin.LoginController.ProcessRequest(HttpListenerContext context)
The domain is not being managed using a member of the Domain Admins Active Directory role group.
The domain management account does not have permissions to see Fine-Grained Password Policies in Active Directory.
Grant the Active Roles domain management account the permissions to list and read all properties of msDS-PasswordSettings objects living in DOMAIN/System/Password Settings Container/
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center