"Unexpected DN in group" on synchronizing with MS Active Directory
Platform Notice: Server and Data Center Only - This article only applies to Atlassian products on the server and data center platforms.
When synchronising Confluence directory to LDAP you might encounter an error like this:
2020-11-19 12:12:16,852 DEBUG \[Caesium-1-2] \[atlassian.crowd.directory.RFC4519DirectoryMembershipsIterable] apply Unexpected DN in group 'confluence-users': cn=user1,ou=my-ou,dc=domain,dc=local
The error above is shown for groups that were already synced into Confluence before.
Confluence Server/Data Center
- MS Active Directory user directory.
- Verify if the OU name has changed before the latest synchronization.
Whenever Confluence is comparing the users it already has synchronized against the set of users it just got from the AD after syncing the directory, it'll log that Unexpected DN in group when it doesn't find the user in the group it was originally a member of, in the output from the LDAP anymore.
Because of that whenever an OU name is changed it might throw the error above.
Changing the OU name back to the original name can solve this in some instances.