Skip to main content

Troubleshooting

A Vertex request can fail at two points:

  • Right away, when Vertex refuses it: the API answers with an RFC 7807 problem and a code (Refused requests).
  • Later, when the operation runs: the operation ends failed (or timeout, cancelled) with an error_code and an error message (Failed operations).

Refused requests​

CodeHTTPMeaning and what to do
not_configured409No connector or AD account is set for the tenant. Save the directory settings.
connector_unavailable409Saving the settings: the chosen connector does not exist (any more) or cannot run Vertex jobs. Choose a connector on a domain controller with a current version (Setting up the domain controller).
writes_disabled409This kind of change (users, groups, OUs, GPOs, password policies) is switched off in the directory settings.
deletes_disabled409Deletes are switched off in the directory settings.
out_of_scope403The object, or the target OU, is outside the managed OUs. Vertex only changes objects below them.
protected403The object is privileged or built-in (adminCount=1, a critical system object, a built-in account or group), or one of the default domain policies. Vertex never changes it; do it on the domain controller if it must be done.
forbidden403Your role does not allow this, for example a helpdesk user changing a non-contact attribute (Roles).
rate_limited429More than 600 changes by you or 2,000 in the tenant in the last minute. Wait a minute.
step_up_required403The action needs a step-up: confirm your password on the Hub and send the token.
step_up_unavailable503Step-up confirmation is not available on this server.
sync_running409A directory sync is already running.
operation_finished409Cancelling an operation that has already finished.
import_not_validated409The import is not waiting for a commit: it was committed, cancelled, or uploaded more than 24 hours ago.
axis_unavailable503Vertex could not reach Entrosity Axis to queue the job; the operation is recorded as failed with this code. Try again; if it persists, see Running Entrosity Vertex.
not_found404The object, GPO, import or operation does not exist in the tenant (or not in the mirror yet: run a sync).
validation, invalid_request422The request is not valid; detail or fields say which value.

Settings validation (422)​

invalid_username (ad_username must be DOMAIN\name or name@domain), invalid_server, invalid_managed_ou (not a DN, or more than 100), invalid_default_ou (not a managed OU or below one), invalid_upn_suffix, invalid_attribute, invalid_interval (5 to 1,440 minutes), invalid_password, password_required (the first save needs the AD password).

Import validation (422)​

invalid_mode, invalid_csv (no header row, or a line that cannot be read; the detail names the line), empty_csv, too_many_rows (more than 10,000), unknown_columns, duplicate_column, missing_column (no sAMAccountName), invalid_column (an attr: column that is not allowed). Problems of single rows do not stop the upload; they make the row invalid (Bulk import → Preview).

Failed operations​

These are the error_code values of failed operations. Most come from the connector or the PowerShell script on the domain controller; the error message has the details (for AD errors, Windows' own message).

The connector's guard​

CodeMeaning and what to do
guard_pendingA local administrator of the domain controller has not accepted Vertex yet, or the managed OUs changed and the new list waits for acceptance, or the guard file is not trusted. Run rmm-connector vertex guard show and accept on the domain controller; accept --ou must name exactly the managed OUs in Vertex's settings (The local guard).
guard_deniedThe kind of change (gpo, pso, …) or deletes are switched off in the local guard: rmm-connector vertex guard set --gpo on (or --pso, --deletes, …).
rate_limitedThe connector's local cap of writes per minute (default 1,000) is reached, usually by several imports or large membership changes within a minute. Wait a minute and retry, or raise the cap (up to 2,000) with vertex guard set --max-writes-per-minute N (The write cap).
expiredThe job reached the connector after its expiry (the connector was offline for an hour, six for imports). Nothing was changed. Send it again.

Checks on the domain controller​

CodeMeaning and what to do
out_of_scopeThe script found the object (or target) outside the managed OUs, for example because it was moved since the last sync, or a password policy outside the Password Settings Container.
protectedThe object, a member to add, or the GPO is protected.
denied_attributeAn attribute on the deny list.
invalid_payloadThe request does not fit the object, for example the object is a group but was addressed as a user, or a password is missing.

Access and setup​

CodeMeaning and what to do
logon_failedThe AD account's user name or password was refused (wrong password, account disabled, locked out or expired). Correct it in the directory settings.
access_deniedThe AD account lacks a right. If the message says may not open a PowerShell session on the domain controller (add it to Remote Management Users), add the account to Remote Management Users (Setting up). Otherwise Active Directory refused the change itself: delegate the right on the OU, the GPO or the Password Settings Container. A live read of the object shows which attributes the account may write.
missing_moduleThe ActiveDirectory or GroupPolicy PowerShell module is not installed on the domain controller (PowerShell and its modules).
unauthorizedVertex refused to hand the job its secrets; nothing was changed. The message says why: author_revoked (the author no longer holds the right: their role was changed or they were deactivated after the request), writes_disabled / deletes_disabled (the switch was turned off meanwhile), expired (the operation expired), secrets_used (the job asked twice), or the operation is no longer live (cancelled, or the tenant now uses another connector).
unsupportedThe connector cannot run Vertex jobs (not a Windows build) or does not know the operation (update the connector).

Directory errors​

CodeMeaning and what to do
not_foundThe object, a group or a member does not exist (any more). Run a sync.
already_existsAn object with this name or logon name already exists.
password_policyThe password does not meet the domain's (or the user's fine-grained) password policy: length, complexity, history or minimum age.
ad_errorAny other error of Active Directory or PowerShell; the message is Windows' own. Also used when the script's results could not be delivered.

Operations that did not run​

CodeMeaning
timeoutThe operation did not finish in time (10 minutes for a change, 30 for a read, an hour for an import batch), or Axis did not answer for an hour after its expiry. Check the result in the directory (a live read) before trying again.
cancelledCancelled by a user.
not_dispatchedThe job was never handed to Axis.
job_lostAxis no longer knows the job.

Common situations​

Everything fails with guard_pending​

The guard has not been accepted, the OUs accepted with --ou are not exactly the managed OUs in Vertex's settings, or the managed OUs were changed in Vertex. Compare rmm-connector vertex guard show with the settings. See Changed managed OUs.

The test fails with access_denied​

The AD account is not in Remote Management Users, or WinRM is off on the domain controller (Setting up the domain controller).

Objects are missing or out of date​

Lists come from the mirror. Run a sync, or a live read of one object. A sync that failed shows last_sync_status and last_sync_error in the settings.

A user cannot be changed although it is in a managed OU​

It is protected: it is (or was) a member of an administrative group (adminCount=1), or a built-in account.

Where to look​

  • The operation (GET …/operations/{operationID}): error_code, error, the requested params (never passwords) and the result.
  • The tenant's audit log: every change and settings change, with its author.
  • On the domain controller: rmm-connector vertex guard show, and the connector's log %ProgramData%\RMM Connector\logs\connector.log.
  • The Axis job of the operation in Axis (the connector's jobs).