The operation failed because spn value provided for addition/modification is not unique forest-wide

This post describes how to fix the error:

The operation failed because spn value provided for addition/modification is not unique forest-wide


Cause

This error occurred when I demoted a child Active Directory domain controller then tried to rejoin the parent domain.  I think the parent domain still had some record of the SPN which I was not able to delete.  By default, Windows checks to ensure the SPN is unique.


Resolution

To resolve this issue, I disabled the uniqueness check as follows:

1. Open ADSI Edit.

2. Right click the ADSI Edit root node in the tree view on the left then select Connect to...

3. In Connection Settings, change the Naming Context to Configuration then press OK

Screenshot showing ADSI Edit Connection Settings with Naming Context set to Configuration


4. Navigate down to CN=Windows NT then right click CN=Directory Service and select Properties

Screenshot showing ADSI Edit Directory Service right click menu with Properties option highlighted


5. Double click dSHeuristics and change the value to 000000000100000000023 to disable the UPN and SPN uniqueness checks.

Screenshot showing dSHeuristics attribute

More information: https://support.microsoft.com/en-us/topic/duplicate-spn-check-on-windows-server-2012-r2-based-domain-controller-causes-restore-domain-join-and-migration-failures-aa11508f-7dfd-4444-835b-7febc303ed5e


Related Posts

The time between replications with this source has exceeded the tombstone lifetime

Error 0x2015(The directory service can perform the requested operation only on a leaf object.)

- Windows cannot delete object LDAP://... because: A referral was returned from the server.

- Active Directory Audit & Reporting Tool

Comments

Popular posts from this blog

LG TV This app will now restart to free up more memory

LG TV Clear All Browsing History Data

Excel Import CSV not using "Use First Row as Headers"