Network Management
UDT AD monitoring import fails with “License limit doesn't allow to add all selected DCs” when DCs are already monitored as nodes
When adding Active Directory Domain Controllers for UDT user logon tracking, the Import AD Domain Controllers wizard can show “License limit doesn't allow to add all selected DCs” even when the DCs are already monitored as nodes and there is sufficient license capacity.
First published date
Last published date
Overview
During UDT configuration for tracking Active Directory user logins, the AD Domain Controller import workflow may block the import with a license-limit message.
This can happen even if the selected Domain Controllers are already present in the SolarWinds Platform as monitored nodes and are actively being polled.
In these cases, the message is misleading and is thrown by the import wizard rather than reflecting a real license-capacity issue.
Product section
Resolution
Because the affected DCs are already added as nodes, the fix is to enable AD polling directly on each existing node instead of going through the Import AD Domain Controllers wizard:
-
Edit each Domain Controller node.
-
Enable the checkbox "Poll to monitor Active Directory users logged in to your network."
-
Save the change.
-
Go to Settings > All Settings > UDT Settings > Manage Active Directory Domain Controller, select the DC, and assign the appropriate Security Log Access credential.
-
Run Poll Now on the node (or from the UDT Job Status page) and confirm polling succeeds.
While assigning credentials, also confirm that the account used has:
-
Event Log Readers permission on each domain controller.
-
Access to the CIMV2, directory, and RSOP WMI namespaces on each domain controller.
A missing permission in this account is the most common reason polling continues to fail after the DC has already been added as a node. Testing the change on a single DC first (before rolling it out to the remaining DCs) is recommended to confirm success before applying it broadly.