Active Directory Account Data Collector (ADC) incorrectly collects null value for PwdLastSet as date 9999-12-31 in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-04
Article Number
Applies To
RSA Version/Condition: 7.1.0, 7.1.1
Issue
If the PwdLastSet attribute in Microsoft Active Directory (AD) is null, RSA Identity Governance & Lifecycle's AD Account Data Collector (ADC) incorrectly collects the value as the date 9999-12-31 with a time value that represents the time of the last collection.
For example, the PwdLastSet attribute may be collected as 9999-12-31 12:45:50. Since the time portion of the attribute may change between subsequent collections, this may incorrectly cause the Account to be marked as Changed even though there was no change to the collected values.
Cause
This is a known issue reported in engineering ticket ACM-92309.
Resolution
- RSA Identity Governance & Lifecycle 7.1.0 P07
- RSA Identity Governance & Lifecycle 7.1.1 P02
- RSA Identity Governance & Lifecycle 7.2
Notes
Related Articles
Duplicate User Groups 7Number of Views Source variable and target variable are showing duplicate values when adding a new value on Next Value node in RSA Via Lif… 35Number of Views Duplicate User IDs 99Number of Views Close an Active User Session 17Number of Views How to remove endpoint agents from RSA Data Loss Prevention 9.6 and later that have been inactive for a long time from Ent… 10Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?