"Failed to decrypt password" error in the RM Unify User Audit log
Published Date : 06 Nov 2023
Content Ref: TEC9448926
Operating System
MS Windows 2016 Server, MS Windows 2019 Server
Part No
(none)
Summary
Explains the cause of the error "Failed to decrypt password" in the RM Unify User Audit log.
Symptoms
RM Unify User Audit log contains the following error event:
Update AD User ERROR. User <username>. Failed to decrypt password
For the same user, you may also see a successful password change event:
Update AD User SUCCESS. User: <username>. [AD]: New Password Set. [AD]: User Updated.
Cause
The RM Unify Network Agent should only be running on one domain controller (DC) on the network, so this issue can occur when you have two DCs running the RM Unify Network Agent service, most likely as a result of installing the RM Unify Network Agent to a new DC but failing to stop and uninstall the Agent from the original DC.
Both the running Agents will receive the same user message from RM Unify and try to process it. As passwords are encrypted with a DC-specific key, only one DC will be able to decrypt the received password change and apply it to the user's AD account. The other DC will fail to decrypt the password change and report an error to the RM Unify User Audit log. This explains why you see both a successful password change event and a failed attempt.
Procedure
Stop and disable the RM Unify Network Agent service on the old DC.
Using the RM Unify User Audit log, confirm if the new changes to RM Unify users continue to be successfully processed on your AD by the remaining RM Unify Network Agent service.
Confirm if a user can:
Change their password in RM Unify and successfully sign into RM Unify and the school network using the new password.
Change their AD password and successfully sign into RM Unify with the new password.
Check if no new errors are being logged to the RM Unify User Audit log.
On the old DC, uninstall the RM Unify Network Agent application from Programs and Features.
If this article has not helped provide a solution then it is also possible to
log a call...