Unable to create user account in Active Directory
The common causes for unsuccessful user creation in Active Directory (AD) and the troubleshooting tips are listed here.
Possible Cause 1:
The user trying to create new accounts might not have the required privileges.
Solution:
- Open the Active Directory Users and Computers console.
- Create a security group and add the users you wish to delegate the user creation task to.
- Right click on the security group, and select Delegate Control.
- Assign the group or the desired user you wish to delegate control to in the Select Users, Computers, or Groups window. Click OK and then Next.
- In the Tasks to Delegate section, select Create, delete and manage user accounts and click Next.
- Click Finish.
ADManager Plus allows OU level granular delegation of Active Directory administration tasks with an audit report to keep track of the tasks done by delegated users.
Possible Cause 2:
The password configured for the user might not meet the password complexity policies set up for the organization.
Solution:
- Navigate to Start > Administrative tools > Group Policy Management
- In the Domain tree, double-click the Domain where you wish to create the user. The GPOs linked to the domain will get listed.
- RIght click the Default Domain Policy and click Edit.
- The Group Policy Editor will pop up. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policy. Double click the Password Policy Setting to view the password policy settings for the domain.
- Ensure the password you set for the new user accounts meet these complexity standards.
With ADManager you can automatically set strong passwords that meet the password complexity policies, and generate reports on the password status of user accounts without PowerShell scripting.
Possible Cause 3:
The sAMAccount name or the User Principal Name already exists.
Solution:
Try creating the user account again with a unique sAMAccount name.
Possible Cause 4:
The global RID pool might be exhausted.
Solution:
- On the Domain Controller, Navigate to Start >Run . Enter ldp.exe and click OK.
- On the Connection menu, click Connect, and then connect locally by using an enterprise administrator account.
- Click Modify on the Browse menu.
- Update the sidCompatibilityVersion attribute to 1. To do so, type this in the Edit Entry Attribute Box:
[Add] sidCompatibilityVersion: 1 - Press Enter, and then click Run.
ADManager Plus is a web-based console which can help you administer your Active Directory, Exchange, Office 365, G- Suite, Skype for Business (Lync) and more from a single application. ADManager Plus' most sought after user management functionalities include,
- Provision user accounts in AD, Exchange, Office 365 (Microsoft 365), lync (Skype for business), and more in one go.
- Customizable user provisioning templates
- Create users in bulk by importing a CSV file with the required attributes
- Automated user provisioning through integration with HR applications like UltiPro, BambooHR, Workday, Zoho People and more.
Download the 30-day fully functional ADManager Plus trial now!
Manage Active Directory computer attributes
ADManager Plus is a web-based tool which offers the capability to manage Active Directory computers in bulk easily using CSV files or templates. Get instant reports on Active Directory computers and export them in CSV, PDF, HTML and XLSX formats.
Unravel end-to-end Active Directory management with ADManager Plus
-
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Hybrid AD, cloud, and file auditing and security
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
