Troubleshooting self-managed Active Directory
The following are issues you might encounter when you set up or modify self-managed AD.
Error Code | Description | Common causes | Troubleshooting suggestions |
---|---|---|---|
Error 2 / 0x2 |
|
The format or location for the Organizational Unit (OU) specified with the |
Review the |
Error 5 / 0x5 |
|
Misconfigured permissions for the domain service account, or the computer account already exists in the domain. |
Review the domain service account permissions in the domain, and verify that the RDS computer account is not duplicated in the domain. You can
verify the name of the RDS computer account by running |
Error 87 / 0x57 |
|
The domain service account specified via AWS Secrets Manager doesn't have the correct permissions. The user profile may also be corrupted. |
Review the requirements for the domain service account. For more information, see Configure your AD domain service account. |
Error 234 / 0xEA |
|
The OU specified with the |
Review the |
Error 1326 / 0x52E |
|
The domain service account credentials provided in AWS Secrets Manager contains an unknown username or bad password. The domain account may also be disabled in your self-managed AD. |
Ensure the credentials provided in AWS Secrets Manager are correct and the domain account is enabled in your self-managed Active Directory. |
Error 1355 / 0x54B |
|
The domain is down, the specified set of DNS IPs are unreachable, or the specified FQDN is unreachable. |
Review the |
Error 1722 / 0x6BA |
|
There was an issue reaching the RPC service of your AD domain. This might be a service or network issue. |
Validate that the RPC service is running on your domain controllers and that the TCP ports |
Error 2224 / 0x8B0 |
|
The computer account that's attempting to be added to your self-managed AD already exists. |
Identify the computer account by running |
Error 2242 / 0x8c2 |
|
The password for the domain service account specified via AWS Secrets Manager has expired. |
Update the password for the domain service account used to join your RDS for SQL Server DB instance to your self-managed AD. |