| Previous | Next |
| ERROR_DS_CANT_RETRIEVE_SD | ERROR_DS_WRONG_LINKED_ATT_SYNTAX |
ERROR_DS_KEY_NOT_UNIQUE
The object requested was not found, but an object with that key was found.
ERROR_DS_KEY_NOT_UNIQUE belongs to Active Directory Domain Services (AD DS). A diagnosis of this result must connect the condition to the producing API, current state, object identity, and first lower-level diagnostic.
This result is Win32 error 8527 (0x0000214F) in Active Directory Domain Services (AD DS). Interpret it at the call that produced it and use the system message above as the immediate condition rather than as a complete root cause.
Where the result appears
- processing a directory lookup where the requested object is absent but another object uses the same key.
- executing an LDAP, RPC, deployment, replication, or directory-management operation.
- working against a specific domain controller whose replica and schema state affect the result.
- translating extended directory diagnostics into a Win32 error for an application or administration tool.
State boundary to prove
This result applies to a directory lookup where the requested object is absent but another object uses the same key and does not by itself prove that the entire server, directory, disk, session, or application is unavailable. The state boundary to prove for it is whether the key used by the application uniquely identifies exactly one intended directory object. Use requested identity and key, all objects matching the key, and object GUIDs and replication metadata as independent evidence. When evidence for it disagrees, preserve timestamps and investigate the transition instead of selecting the most convenient value.
Likely causes
- a stale or duplicate key exists.
- the lookup combines an object identity with a non-unique alternate key.
- replication conflict created ambiguous metadata.
- the caller searches the wrong partition.
Diagnostic sequence
- capture error 8527 immediately at the API boundary and record the operation that was attempted.
- identify the exact owner of a directory lookup where the requested object is absent but another object uses the same key, including object generation, server, path, session, replica, or client context.
- collect requested identity and key before restarting a service or changing configuration.
- compare all objects matching the key with the documented or observed precondition.
- correlate object GUIDs and replication metadata with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace.
- determine whether side effects occurred and verify recovery after changing one responsible condition.
Evidence to collect
- requested identity and key.
- all objects matching the key.
- object GUIDs and replication metadata.
- search base and contacted DC.
Correlate it with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace. Keep the first detailed status even when a later wrapper translates it to error 8527; the first status often distinguishes transport, authorization, storage, schema, state, and application-integrity causes that share the same final Win32 result.
Handling, retry, and recovery
The recovery objective is to resolve the duplicate or stale key through supported directory management, refresh the caller identity, and avoid selecting an arbitrary match.
Retry it only after the recorded condition changes and completion state is known. Idempotent queries may be repeated after recovery, but mutations require a state check first; backoff cannot repair malformed input, corruption, missing structure, or policy rejection.
Telemetry and support fields
- record
ds_key_not_unique_apifor the producing function or management operation. - record
ds_key_not_unique_targetfor the file, log, session, replica, object, or server identity. - record
ds_key_not_unique_state_beforeandds_key_not_unique_requested_transition. - record
ds_key_not_unique_first_statusfor the earliest lower-level diagnostic.
For support escalation involving it, retain decimal 8527, hexadecimal 0x0000214F, the API, UTC time, target identity, and first subsystem-specific status. Include the smallest reproducible request and evidence that distinguishes this condition from nearby codes. In the context of it, many ds codes are internal or management-facing and are not tied to one public function. the producing ldap, rpc, deployment, or management api must therefore be recorded with the code.
Difference from nearby results
ERROR_DS_NAME_NOT_UNIQUE is specifically about a name used as a unique identifier; this code can concern another directory key
Practical validation scenario
An application searches for a deleted object GUID plus an alternate key now used by a replacement. Refreshing its stored object identity removes the ambiguity. The negative test should preserve the responsible condition and reproduce it; the recovery test should change only the identified cause, repeat the same operation, and verify both success and the absence of an unintended partial side effect.
Developer and administrator guidance
Administrators handling it should preserve Directory Service events, replication metadata, and the contacted domain controller before changing objects or forcing role transitions. Developers should retain LDAP extended diagnostics and object identities across wrappers so the Win32 code does not erase the actionable directory result. Code that exposes it through RPC, JSON, REST, PowerShell, or another protocol should preserve the Win32 domain, decimal 8527, hexadecimal 0x0000214F, and original component diagnostic.
References
- Microsoft: Win32 system error range containing this code — official context relevant to it.
- Microsoft: AD DS troubleshooting — official context relevant to it.
- Microsoft: repadmin — official context relevant to it.
- Microsoft: dcdiag — official context relevant to it.
- Microsoft: AD and LDS diagnostic event logging — official context relevant to it.
Looking for a different code? Search another status or error code.