Using SSPR 3.2 that shipped with IDM 4.5. I see some similar threads,
but none with a solution. Users are created with logindisabled set to
true. When I try to activate the user, I get the following error:

Unable to establish session password. { 5026 ERROR_BAD_SESSION_PASSWORD
(unable to authenticate with admin retrieved password, check proxy
rights, ldap logs; error: 5066 ERROR_ACCOUNT_EXPIRED (unable to create
connection: unable to bind to ldaps:// as
cn=CATA1,ou=users,o=data reason: [LDAP: error code 53 - NDS error: log
account expired (-220)])) }

The log shows the same error. If I set logindisabled to false and
change the Activation Permission filter appropriately, activation works.
Is it no longer possible to activate disabled users? I have done this
with previous versions. If it is possible, what do I need to do to
allow it?

