RocketChat/Rocket.Chat · error · Error

LDAP_disabled

LDAP_disabled

Error message

LDAP_disabled

What it means

Error `LDAP_disabled` thrown by ldap.syncNow when the LDAP_Enable setting is not exactly true. The endpoint exists whenever the enterprise LDAP package is loaded, but refuses to start a sync against a workspace where LDAP login is switched off, since there is no configured directory to sync.

Solutions

  1. Enable LDAP in Administration > LDAP (LDAP_Enable = true) with a working server configuration, then retry the sync.
  2. Pause/queue ldap.syncNow automation while LDAP is intentionally disabled.
  3. Preflight the setting so failures surface as configuration errors, not API errors.

Example fix

// before
await POST('ldap.syncNow'); // LDAP_disabled

// after
await POST('settings/LDAP_Enable', { value: true });
await POST('ldap.syncNow');
Defensive patterns

Strategy: validation

Validate before calling

const ldapEnabled = async (): Promise<boolean> => (await GET('settings/LDAP_Enable')()).value === true;

Type guard

const isLdapDisabled = (error: unknown): boolean =>
	Boolean(error && typeof error === 'object' && 'message' in error && (error as Error).message.includes('LDAP_disabled'));

Try / catch

try {
	await POST('ldap.syncNow');
} catch (error) {
	if (isLdapDisabled(error)) {
		// configuration problem, not transient: report and stop
		throw new ConfigurationError('LDAP is disabled on this workspace');
	}
	throw error;
}

Prevention

When it happens

Trigger: POST /v1/ldap.syncNow after LDAP was disabled in Administration > LDAP, or before initial LDAP configuration was enabled.

Common situations: Sync scripts running while admins reconfigure LDAP; freshly restored workspaces where LDAP_Enable reset to default false; temporarily disabling LDAP and forgetting dependent automation.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/b529f2b6e2eccf3e. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/ee/server/api/ldap.ts:40

		forceTwoFactorAuthenticationForNonEnterprise: true,
		twoFactorRequired: true,
		response: {
			200: ldapSyncNowResponseSchema,
			400: validateBadRequestErrorResponse,
			401: validateUnauthorizedErrorResponse,
		},
	},
	async function action() {
		if (!this.userId) {
			throw new Error('error-invalid-user');
		}

		if (!(await hasPermissionAsync(this.user, 'sync-auth-services-users'))) {
			throw new Error('error-not-authorized');
		}

		if (settings.get('LDAP_Enable') !== true) {
			throw new Error('LDAP_disabled');
		}

		await LDAPEnterprise.sync();
		await LDAPEnterprise.syncAvatarAndAbacAttributes();

		return API.v1.success({
			message: 'Sync_in_progress' as const,
		});
	},
);

View on GitHub (pinned to b2c16d5842)