Attempting to update the samAccountName attribute fails with the ERROR: Directory service is unavailable.
This issue occurs in all Active Roles clients.
All other attributes can be updated without issue.
There is a firewall or other appliance between the Active Roles Administration Service and the target Active Directory Domain Controller and the appliance is performing SSL packet inspection on port 389.
The SSL packet inspection is interrupting the LDAP calls and is interfering with the samAccountName attribute update.
WORKAROUND 1
WORKAROUND 2
Disable SSL packet inspection on port 389 between the Active Roles Administration Service and the target Active Directory Domain Controllers.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center