Troubleshoot Connector for AD directory registration failures
Connector for AD directory registration can fail for various reasons. When directory registration fails, you'll receive the failure reason in the API response. If you're using the console, you can find the failure reason in the Directory registration details pane under the Additional status information field. The following table describes failure reasons and recommended steps for resolution.
| Failure status | Description | Remediation |
|---|---|---|
DIRECTORY_ACCESS_DENIED |
Connector for AD is unable to access your directory. |
Connector for AD doesn't support creating a directory registration or a connector in a replica Region of a multi-Region AWS Managed Microsoft AD directory. If you attempted to create a directory registration in a replica Region, delete the failed directory registration and create a new one in the directory's primary Region. Create your connector in the primary Region as well. For information about multi-Region replication, see Multi-Region replication in the AWS Directory Service Administration Guide. You must grant Connector for AD access to your directory. Review the Step 4: Create IAM Policy section to make sure that the IAM policy associated with your AWS account enables you to access and describe directories. After granting the correct permissions to your AWS role, delete the failed directory registration and create a new one. If you use Connector for AD with an AWS Directory Service AD Connector, make sure that the AD Connector service account's password isn't expired and is valid. For information about AD Connector service accounts, see Getting started with AD Connector in the AD Connector Administration Guide. |
DIRECTORY_NOT_ACTIVE |
Your directory isn't in the Active state. |
Your directory must be in the |
DIRECTORY_NOT_REACHABLE |
Connector for AD can't reach your directory. |
Check the network between AWS and your directory, then delete the failed directory registration and create a new one. |
DIRECTORY_RESOURCE_NOT_FOUND |
Connector for AD can't find the specified directory. |
Make sure that you specify the correct directory ID, then delete the failed directory registration and create a new one using your intended directory ID. |
DIRECTORY_TYPE_NOT_SUPPORTED |
Connector for AD doesn't support this directory type. |
Connector for AD supports AWS Managed Microsoft AD (Standard and Enterprise editions) that you own, and AD Connector directories. Connector for AD doesn't support the Hybrid edition of AWS Managed Microsoft AD or directories that another account shares with yours. For a shared directory, create the directory registration in the AWS account that owns the directory. |
INTERNAL_FAILURE |
Connector for AD experienced an internal failure. |
Try again later. Delete the failed directory registration and create a new one. |