LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042F, comment: AcceptSecurityContext error, data 52e
Active Directory/LDAP rejected the bind — the data code tells you why (52e wrong password, 525 user not found, 532 password expired, 533 disabled, 775 locked).
Seen on:
REST API
Meaning
Applications (Jenkins, GitLab, Grafana, Java/PHP apps) binding to AD with a service account fail when its password expires or the bind DN format is wrong. The “data xxx” code is the key.
Common causes
- Wrong password (52e) or user DN/UPN (525)
- Service account password expired (532) or must change (773)
- Account disabled (533) or locked (775)
- Bind DN format wrong (use UPN or full DN)
⚡ Quick fix
- Decode the data code and fix that cause
- Use user@domain (UPN) or the full DN for binds
- Set service account passwords to non-expiring per policy
Detailed fix by platform
Shell
ldapwhoami -x -H ldaps://dc01.corp.example.com -D "svc_app@corp.example.com" -W
How to diagnose
- Code — data 52e/525/532/533/701/773/775
- DN — Format used
- Account — Status in AD
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- Clock skew too great Kerberos: Clock skew too great (KRB_AP_ERR_SKEW)
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026