# Use Keycloak as IAM

**URL:** <https://forum.keycloak.org/t/use-keycloak-as-iam/9636>\
**Category:** Getting advice\
**Tags:** ldap\
**Created:** [June 17, 2021, 10:27am UTC](https://forum.keycloak.org/t/use-keycloak-as-iam/9636 "2021-06-17T10:27:18Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jol002](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jol002/32/2418_2.png) [@jol002](https://forum.keycloak.org/u/jol002)\
**Post date:** [June 17, 2021, 10:27am UTC](https://forum.keycloak.org/t/use-keycloak-as-iam/9636/1 "2021-06-17T10:27:19Z")

</div>

While trying to change a password in Keycloak, the following message appears:

- In Keycloak: Could not modify attribute for DN [CN=xxxx,OU=Users,OU=xxxx,DC=xxxx,DC=xxxx,DC=com] (I replaced sensitive values by xxxx, for security-reasons)
- In AD (eventviewer): Password propagation is not done. Either default encryption key is configured or no UNIX hosts configured to propagate password

The bind username/password are from an admin-account, with full admin-rights in AD.  
The LDAP edit-mode is set to ‘WRITABLE’. I’ve tried with Sync Registrations OFF and ON, both with the same result.  
Does anyone know how to solve this?
