Some or all identity references could not be translated

One of the unexpected occurrences in a segregated IT environment is that an action intended to help one organization may inadvertently harm others. For example, when the Active Directory (AD) team deletes an inactive service account as part of a cleanup process, it may seem well justified from their perspective. However, that account could still be linked to SharePoint’s managed accounts, which must be cleaned up before its deletion in AD. If this cleanup is overlooked, SharePoint will display an error on the Central Admin's "Configure Service Accounts" page at <https://CentralAdminUrl>/_admin/FarmCredentialManagement.aspx:

Some or all identity references could no be translated

Diagnosis/Remedy


1. Navigate to the Managed Accounts page in Central Admin at <https://caUrl>/admin/ManagedAccounts.aspx.

2. Check if any service accounts listed are missing a value in the PasswordExpiration column. You can also retrieve the info in PowerShell by running Get-SPManagedAccount:
Missing PasswordExpiration Value

3. If any missing values are found under PasswordExpiration, check for the account's existence in AD.
    a. If the account is not found in AD but is still needed for SharePoint:
        - Restore the account from the AD recycle bin (or re-create it if it can't be restored)
        - Ensure the account is not locked out or disabled
    b. If the account is no longer needed for SharePoint, remove it from Managed Accounts by calling the Delete() method in PowerShell as follows (note that Remove-SPManagedAccount will not work):

4. Confirm the absence of blank PasswordExpiration values:

5. Now the Service Accounts page is restored:




Popular posts from this blog

October 2025 SharePoint CU Failed to Install After Applying September 2025 SharePoint CU

September 2025 SharePoint 2016 CU - Configuration Wizard failed

Broken Site Collection