How to exclude RSA Authentication Manager 8.x from picking up disabled user account data from the Microsoft LDAP directory
Originally Published: 2018-06-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
Resolution
- Login to the Operations Console of the primary Authentication Manager instance.
- Click Deployment Configuration > Identity Sources > Manage Existing.
- When prompted, enter the super admin user ID and password
- Click the context arrow for the identity source in question and select Edit.
- Click the Connection(s) tab or the Map tab to view the properties of the external identity source:
- Scroll down to the Directory Configuration - Users section and modify the default search filter from (&(objectClass=User)(objectcategory=person)) to the string below:
(&(objectClass=User)(objectcategory=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
- Once done, click Save and Finish for the changes to take effect.
- Login to the Security Console for the primary.
- Verify that the disabled user accounts from the Microsoft LDAP Directory are filtered.
Notes
Related Articles
How to exclude directories on a Datacenter agent - RSA DLP 22Number of Views Enable a User Account 2Number of Views How to exclude files based on a regular expression in RSA Access Manager Agents 26Number of Views Active Directory Account Collector fails with 'Naming Exception happened' in RSA Identity Governance & Lifecycle 258Number of Views Disable User Sync 17Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?