# KC-SERVICES0013: Failed authentication: org.keycloak.storage.ReadOnlyException:

**URL:** <https://forum.keycloak.org/t/kc-services0013-failed-authentication-org-keycloak-storage-readonlyexception/23178>\
**Category:** Miscellanaeous\
**Created:** [October 31, 2023, 7:18pm UTC](https://forum.keycloak.org/t/kc-services0013-failed-authentication-org-keycloak-storage-readonlyexception/23178 "2023-10-31T19:18:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![keycloak560](https://avatars.discourse-cdn.com/v4/letter/k/cdc98d/32.png) [@keycloak560](https://forum.keycloak.org/u/keycloak560)\
**Post date:** [October 31, 2023, 7:18pm UTC](https://forum.keycloak.org/t/kc-services0013-failed-authentication-org-keycloak-storage-readonlyexception/23178/1 "2023-10-31T19:18:37Z")

</div>

Hi Team,

We have insalllted keycloak standalone version 21.1.0 on window server 2019, and configured user federation with Microsoft AD. we are trying to enable google authentication (CONFIGURE\_TOTP) on keycloak but keycloak trying to write user attributes and action ON microsoft AD LDAP. Keycloak server providing below error.  
KC-SERVICES0013: Failed authentication: org.keycloak.storage.ReadOnlyException: Not possible to write ‘required action CONFIGURE\_TOTP’ when updating user ‘xxxxxx@xxxxxxx.com’. Along with we have added user attributes in microsoft AD LDAP and added new attributes not visiable on keycloak. so how can keycloak write issue will be solved.

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [October 31, 2023, 9:29pm UTC](https://forum.keycloak.org/t/kc-services0013-failed-authentication-org-keycloak-storage-readonlyexception/23178/2 "2023-10-31T21:29:24Z")

</div>

I don’t know your AD User Federation configuration, but most probably, you have set the “Edit Mode” to `READ_ONLY`.  
To be able to store data in Keycloak, like required actions and other user attributes, you should set it to `UNSYNCED`.
