<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIFS Not joining AD Controller in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138984#M30676</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="login-bold"&gt;&lt;A id="link_2" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.netapp.com/t5/user/viewprofilepage/user-id/49683" target="_self"&gt;Abhishar&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="login-bold"&gt;Thanks for the reply but I tried with multiple users of different groups. All the users have Full Control on that particular OU. They can create new OU and delete OUs without a problem manually.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="login-bold"&gt;Tried it again after deleting the OU but results are same.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="login-bold"&gt;No Luck so far.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Mar 2018 08:55:48 GMT</pubDate>
    <dc:creator>arsalankhan</dc:creator>
    <dc:date>2018-03-20T08:55:48Z</dc:date>
    <item>
      <title>CIFS Not joining AD Controller</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138966#M30664</link>
      <description>&lt;P&gt;We are trying to connect Data Ontap 9.3P2 (FAS9000) to AD Domain Controller.&lt;/P&gt;
&lt;P&gt;We are getting below error. Could you please help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ECC_MCC_2::&amp;gt; vserver cifs create -vserver ecc_vs1 -cifs-server eccnas7 -domain aaa.com&lt;/P&gt;
&lt;P&gt;In order to create an Active Directory machine account for the CIFS server,&lt;BR /&gt;you must supply the name and password of a Windows account with sufficient &lt;BR /&gt;privileges to add computers to the "CN=Computers" container within the &lt;BR /&gt;"AAA.COM" domain.&lt;/P&gt;
&lt;P&gt;Enter the user name: bukedj0a&lt;/P&gt;
&lt;P&gt;Enter the password:&lt;/P&gt;
&lt;P&gt;Warning: An account by this name already exists in Active Directory at&lt;BR /&gt; CN=ECCNAS7,OU=NON Windows Systems,OU=EXPEC,OU=Migration &lt;BR /&gt; Production,DC=aaa,DC=com. &lt;BR /&gt; If there is an existing DNS entry for the name ECCNAS7, it must be&lt;BR /&gt; removed. Data ONTAP cannot remove such an entry. &lt;BR /&gt; Use an external tool to remove it after this command completes. &lt;BR /&gt; Ok to reuse this account? {y|n}: y&lt;/P&gt;
&lt;P&gt;Error: Machine account creation procedure failed&lt;BR /&gt; [ 500] Loaded the preliminary configuration.&lt;BR /&gt; [ 503] Successfully connected to ip 10.4.94.180, port 88 using&lt;BR /&gt; TCP &lt;BR /&gt; [ 514] Successfully connected to ip 10.4.94.180, port 389 using&lt;BR /&gt; TCP &lt;BR /&gt; [ 520] Account 'ECCNAS7' already exists in the 'AAA.COM' &lt;BR /&gt; domain &lt;BR /&gt;**[ 521] FAILURE: Could not rename existing account &lt;BR /&gt;** 'CN=ECCNAS7,OU=NON Windows Systems,OU=EXPEC,OU=Migration&lt;BR /&gt;** Production,DC=aaa,DC=com' to &lt;BR /&gt;** 'cn=ECCNAS7,cn=computers,dc=aaa,dc=com': Insufficient&lt;BR /&gt;** access&lt;/P&gt;
&lt;P&gt;Error: command failed: Failed to create the Active Directory machine account&lt;BR /&gt; "ECCNAS7". Reason: LDAP Error: The user has insufficient access rights.&lt;/P&gt;
&lt;P&gt;ECC_MCC_2::&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3/19/2018 14:33:41 cdcnas7 DEBUG secd.unexpectedFailure: vserver (cdc_vs1) Unexpected failure. Error: Machine account creation procedure failed&lt;BR /&gt; [ 470] Loaded the preliminary configuration.&lt;BR /&gt; [ 475] Successfully connected to ip 10.4.94.180, port 88 using TCP&lt;BR /&gt; [ 487] Successfully connected to ip 10.4.94.180, port 389 using TCP&lt;BR /&gt; [ 492] Account 'CDCNAS7' already exists in the 'AAA.COM' domain&lt;BR /&gt;**[ 492] FAILURE: Could not rename existing account 'CN=cdcnas7,OU=NON Windows Systems,OU=EXPEC,OU=Migration Production,DC=aaa,DC=com' to 'cn=CDCNAS7,cn=computers,dc=aaa,dc=com': Insufficient access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried by deleting the object from Domain Controller first and tried again but we are still getting almost same&amp;nbsp;error. Intrestingly we tried with&amp;nbsp;multiple users who have full permission on that OU and can create OU and machine accounts on Domain Controller but couldnt join.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could someone please help..&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Arsalan&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:54:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138966#M30664</guid>
      <dc:creator>arsalankhan</dc:creator>
      <dc:date>2025-06-04T13:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS Not joining AD Controller</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138973#M30666</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Its looks like the account you are using to add vserver in domain doesn't have rights to modify account in AD.&lt;/P&gt;
&lt;P&gt;Please check with AD team and try with different user, also try to give user name like &amp;lt;User_name&amp;gt;@&amp;lt;domain_name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also cross check the secd logs.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/48057"&gt;@arsalankhan&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;We are trying to connect Data Ontap 9.3P2 (FAS9000) to AD Domain Controller.&lt;/P&gt;
&lt;P&gt;We are getting below error. Could you please help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ECC_MCC_2::&amp;gt; vserver cifs create -vserver ecc_vs1 -cifs-server eccnas7 -domain aaa.com&lt;/P&gt;
&lt;P&gt;In order to create an Active Directory machine account for the CIFS server,&lt;BR /&gt;you must supply the name and password of a Windows account with sufficient &lt;BR /&gt;privileges to add computers to the "CN=Computers" container within the &lt;BR /&gt;"AAA.COM" domain.&lt;/P&gt;
&lt;P&gt;Enter the user name: bukedj0a&lt;/P&gt;
&lt;P&gt;Enter the password:&lt;/P&gt;
&lt;P&gt;Warning: An account by this name already exists in Active Directory at&lt;BR /&gt; CN=ECCNAS7,OU=NON Windows Systems,OU=EXPEC,OU=Migration &lt;BR /&gt; Production,DC=aaa,DC=com. &lt;BR /&gt; If there is an existing DNS entry for the name ECCNAS7, it must be&lt;BR /&gt; removed. Data ONTAP cannot remove such an entry. &lt;BR /&gt; Use an external tool to remove it after this command completes. &lt;BR /&gt; Ok to reuse this account? {y|n}: y&lt;/P&gt;
&lt;P&gt;Error: Machine account creation procedure failed&lt;BR /&gt; [ 500] Loaded the preliminary configuration.&lt;BR /&gt; [ 503] Successfully connected to ip 10.4.94.180, port 88 using&lt;BR /&gt; TCP &lt;BR /&gt; [ 514] Successfully connected to ip 10.4.94.180, port 389 using&lt;BR /&gt; TCP &lt;BR /&gt; [ 520] Account 'ECCNAS7' already exists in the 'AAA.COM' &lt;BR /&gt; domain &lt;BR /&gt;**[ 521] FAILURE: Could not rename existing account &lt;BR /&gt;** 'CN=ECCNAS7,OU=NON Windows Systems,OU=EXPEC,OU=Migration&lt;BR /&gt;** Production,DC=aaa,DC=com' to &lt;BR /&gt;** 'cn=ECCNAS7,cn=computers,dc=aaa,dc=com': Insufficient&lt;BR /&gt;** access&lt;/P&gt;
&lt;P&gt;Error: command failed: Failed to create the Active Directory machine account&lt;BR /&gt; "ECCNAS7". Reason: LDAP Error: The user has insufficient access rights.&lt;/P&gt;
&lt;P&gt;ECC_MCC_2::&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3/19/2018 14:33:41 cdcnas7 DEBUG secd.unexpectedFailure: vserver (cdc_vs1) Unexpected failure. Error: Machine account creation procedure failed&lt;BR /&gt; [ 470] Loaded the preliminary configuration.&lt;BR /&gt; [ 475] Successfully connected to ip 10.4.94.180, port 88 using TCP&lt;BR /&gt; [ 487] Successfully connected to ip 10.4.94.180, port 389 using TCP&lt;BR /&gt; [ 492] Account 'CDCNAS7' already exists in the 'AAA.COM' domain&lt;BR /&gt;**[ 492] FAILURE: Could not rename existing account 'CN=cdcnas7,OU=NON Windows Systems,OU=EXPEC,OU=Migration Production,DC=aaa,DC=com' to 'cn=CDCNAS7,cn=computers,dc=aaa,dc=com': Insufficient access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried by deleting the object from Domain Controller first and tried again but we are still getting almost same&amp;nbsp;error. Intrestingly we tried with&amp;nbsp;multiple users who have full permission on that OU and can create OU and machine accounts on Domain Controller but couldnt join.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could someone please help..&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Arsalan&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 00:27:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138973#M30666</guid>
      <dc:creator>Abhishar</dc:creator>
      <dc:date>2018-03-20T00:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS Not joining AD Controller</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138984#M30676</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="login-bold"&gt;&lt;A id="link_2" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.netapp.com/t5/user/viewprofilepage/user-id/49683" target="_self"&gt;Abhishar&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="login-bold"&gt;Thanks for the reply but I tried with multiple users of different groups. All the users have Full Control on that particular OU. They can create new OU and delete OUs without a problem manually.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="login-bold"&gt;Tried it again after deleting the OU but results are same.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="login-bold"&gt;No Luck so far.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 08:55:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/138984#M30676</guid>
      <dc:creator>arsalankhan</dc:creator>
      <dc:date>2018-03-20T08:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS Not joining AD Controller</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/142807#M31699</link>
      <description>&lt;P&gt;Is someone able to fix this issue? If so could you please help me because i am facing the same error i my evironment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bit urgent.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 08:10:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Not-joining-AD-Controller/m-p/142807#M31699</guid>
      <dc:creator>Yogananda</dc:creator>
      <dc:date>2018-09-19T08:10:40Z</dc:date>
    </item>
  </channel>
</rss>

