RocketChat/Rocket.Chat · error · Error
LDAP_disabled
LDAP_disabled
Error message
LDAP_disabled
What it means
Error `LDAP_disabled` thrown by ldap.syncNow when the LDAP_Enable setting is not exactly true. The endpoint exists whenever the enterprise LDAP package is loaded, but refuses to start a sync against a workspace where LDAP login is switched off, since there is no configured directory to sync.
Solutions
- Enable LDAP in Administration > LDAP (LDAP_Enable = true) with a working server configuration, then retry the sync.
- Pause/queue ldap.syncNow automation while LDAP is intentionally disabled.
- Preflight the setting so failures surface as configuration errors, not API errors.
Example fix
// before
await POST('ldap.syncNow'); // LDAP_disabled
// after
await POST('settings/LDAP_Enable', { value: true });
await POST('ldap.syncNow'); Defensive patterns
Strategy: validation
Validate before calling
const ldapEnabled = async (): Promise<boolean> => (await GET('settings/LDAP_Enable')()).value === true; Type guard
const isLdapDisabled = (error: unknown): boolean =>
Boolean(error && typeof error === 'object' && 'message' in error && (error as Error).message.includes('LDAP_disabled')); Try / catch
try {
await POST('ldap.syncNow');
} catch (error) {
if (isLdapDisabled(error)) {
// configuration problem, not transient: report and stop
throw new ConfigurationError('LDAP is disabled on this workspace');
}
throw error;
} Prevention
- Verify LDAP_Enable is true before scheduling sync jobs.
- Pause directory automation while LDAP is being reconfigured.
- After workspace restores, re-check that LDAP settings survived.
When it happens
Trigger: POST /v1/ldap.syncNow after LDAP was disabled in Administration > LDAP, or before initial LDAP configuration was enabled.
Common situations: Sync scripts running while admins reconfigure LDAP; freshly restored workspaces where LDAP_Enable reset to default false; temporarily disabling LDAP and forgetting dependent automation.
Related errors
- error-abac-not-enabled
- error-invalid-user
- error-not-authorized
- error-abac-attribute-store-external
- error-action-not-allowed
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/b529f2b6e2eccf3e.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/ee/server/api/ldap.ts:40
forceTwoFactorAuthenticationForNonEnterprise: true,
twoFactorRequired: true,
response: {
200: ldapSyncNowResponseSchema,
400: validateBadRequestErrorResponse,
401: validateUnauthorizedErrorResponse,
},
},
async function action() {
if (!this.userId) {
throw new Error('error-invalid-user');
}
if (!(await hasPermissionAsync(this.user, 'sync-auth-services-users'))) {
throw new Error('error-not-authorized');
}
if (settings.get('LDAP_Enable') !== true) {
throw new Error('LDAP_disabled');
}
await LDAPEnterprise.sync();
await LDAPEnterprise.syncAvatarAndAbacAttributes();
return API.v1.success({
message: 'Sync_in_progress' as const,
});
},
);
View on GitHub (pinned to b2c16d5842)