Symantec Privileged Access Management

 View Only
  • 1.  Account is disabled

    Posted Jun 22, 2021 01:14 PM
    Edited by everton foster Jun 22, 2021 01:16 PM
    All having an issue within PAM and not sure what is the cause. 

    I get the error message "PAM-CM-1203: Account is disabled" when verifying the password. 

    however the account is not disabled in Active Directory. Has any one seen this error.  I tried to research the error and could not find it on Broadcom's KBase. 



    Thanks again.

    E.


  • 2.  RE: Account is disabled

    Broadcom Employee
    Posted Jun 22, 2021 11:24 PM
    Hello Everton, This error maps to Windows error

    ERROR_ACCOUNT_DISABLED

    1331 (0x533)

    This user can't sign in because this account is currently disabled.

    I don't see how we could show this if we did not get error 1331 back from AD. Did you verify that the DN is configured correctly in the target account and doesn't point to an account different from the one you were looking at?


  • 3.  RE: Account is disabled

    Broadcom Employee
    Posted Jun 23, 2021 10:34 AM
    Everton,

    Confirm that the account is not set with an expiration date.  I don't believe it sets the "account disabled" flag when this date is reached, but all access to the account treats it as though it was disabled.






  • 4.  RE: Account is disabled

    Posted Jun 23, 2021 11:21 AM
    GM All,

    I was able to resolve the issue by creating a new AD target account. I did check all of the above. Not sure why the error. I think maybe the distinguished name may have led back to a deactivated account.  

    Thanks again for your help. Much appreciated.