CIFS create fails with "FAILURE: Unable to set machine account attribute" due to permissions
Applies to
- ONTAP 9
- CIFS/SMB
Issue
- vserver cifs create command fails with the following output.
Error: Machine account creation procedure failed [ 2370] Loaded the preliminary configuration. [ 2518] Created a machine account in the domain [ 2524] SID to name translations of Domain Users and Admins completed successfully [ 2524] Successfully connected to ip 10.xx.xx.xxx, port 88 using TCP [ 2531] Successfully connected to ip 10.xx.xx.xxx, port 464 using TCP [ 2554] Kerberos password set for 'COMPUTERNAME$@DOMAIN.NET' succeeded [ 2554] Set initial account password **[ 2582] FAILURE: Unable to set machine account attribute ** 'msDS-SupportedEncryptionTypes': Insufficient access [ 2589] Deleted existing account 'CN=COMPUTERNAME,OU=NetApp,DC=domain,DC=net' Error: command failed: Failed to create the Active Directory machine account "COMPUTERNAME". Reason: LDAP Error: The user has insufficient access rights.