Article Content
Article Number | 000034559 |
Applies To | RSA Product Set: RSA Identity Governance and Lifecycle RSA Version/Condition: All |
Issue | An AD Account Collector is getting an error on the test group filter when the Group Base DN is set to the root of the LDAP tree (e. g., DC=sub,DC=acme,DC=com). The error message in the UI is: javax.naming.PartialresultException |
Cause | The Active Directory 'follow referrals' configure and group lookup fails when it tries a DNS lookup on the referral in the AD server root. |
Resolution | Turn on the Ignore Referral option in the ADC collector by editing the collector definition, going to the Connection page (page 2), and clicking on the Ignore Referral option as shown below: |