When searching for users that belong to a specific AD domain via the SPE component, it fails with the following error:
"System error occurred. For more information, view the event log"
Password Manager Verbose logging reports the following:
2025-05-05 10:31:37:438 I [5684:155] QPM.Service.Modules.ADHelpers.dll DsContext..ctor() >> DsBindWithCred return Error code : 5
2025-05-05 10:31:37:438 I [5684:155] QPM.Service.Modules.ADHelpers.dll NativeWrapper.makeError() >> makeError Error Message : Access is denied.
The SPE component uses the local machine domain information (domain name, dc name) which are sent to the Password Manager service which enforces to use that one. The problem is that when the user being searched is in a different domain, this issue occurs.
Status:
The Password Manager product team has raised defect #490193. This issue will be fixed in a future version of Password Manager.
Workaround:
1.- Open the regedit from a machine running the SPE component.
2.- Create a DWORD entry under the following path named 'Allow' and value of 1:
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\One Identity\Password Manager
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center