LDAP_ALREADY_EXISTS trying to sync group Everyone to Active Directory

  • 7023189
  • 20-Jul-2018
  • 20-Jul-2018

Environment


Identity Manager X.X (any version)

Situation

When attempting to sync a group from the Identity Vault called Everyone a LDAP_ALREADY_EXISTS error is received.

If you look in Users and Computers, you cannot find any object called Everyone.   However the group will still not sync.

Resolution

Rename the Everyone Group name to something different like AllUsers, then it will synchronize to Active Directory.

Cause

Active Directory has a built in group called Everyone.

Example:
CN=Everyone,CN=WellKnown Security Principals,CN=Configuration,DC=domain,DC=novell,DC=com