Active Directory Account Data Collector (ADC) incorrectly collects null value for PwdLastSet as date 9999-12-31 in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-04
Article Number
Applies To
RSA Version/Condition: 7.1.0, 7.1.1
Issue
If the PwdLastSet attribute in Microsoft Active Directory (AD) is null, RSA Identity Governance & Lifecycle's AD Account Data Collector (ADC) incorrectly collects the value as the date 9999-12-31 with a time value that represents the time of the last collection.
For example, the PwdLastSet attribute may be collected as 9999-12-31 12:45:50. Since the time portion of the attribute may change between subsequent collections, this may incorrectly cause the Account to be marked as Changed even though there was no change to the collected values.
Cause
This is a known issue reported in engineering ticket ACM-92309.
Resolution
- RSA Identity Governance & Lifecycle 7.1.0 P07
- RSA Identity Governance & Lifecycle 7.1.1 P02
- RSA Identity Governance & Lifecycle 7.2
Notes
Related Articles
Duplicate Local Entitlements may occur when Provisioning Local Entitlements through Manual Activities in RSA Identity Gove… 28Number of Views Some entitlements appear duplicated in RSA Identity Governance & Lifecycle 50Number of Views Access Fulfillment Express (AFX) connector export fails with 'Could Not Create Connector Package' and 'duplicate entry' er… 59Number of Views Workaround to remove duplicate identities resulted to mapping of account to a terminated account instead of the active one 76Number of Views Duplicate User IDs 94Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?