Incomplete Collection of AD Groups in RSA Identity Governance & Lifecycle
Originally Published: 2018-01-17
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 7.0.1, 7.0.2
Issue
Group Base DN: DC=CompanyXYZ, DC=com
The search criteria is
(&(objectCategory=Group)(objectClass=group))
The Test button for Group Data in the collector edit screen may indicate that the first 1000 is found.
The Test button may on occasion show a timeout which is not recorded in the aveksaServer.log
Upon collection, only a handful of AD administrative groups show up in the raw data for the collection.
Cause
Because of the referral, you will end up in other parts of the tree for which the account you are using has no access rights, hence you collect less or even nothing.
Resolution
In the collector definition, please make sure that you check the Ignore Referrals box.
This will allow the Collector to find and pull in all groups in the domain.
We also suggest that you use a more targeted entry point in the tree, so that ACM collections do not search unnecessarily large areas.
Related Articles
Change in the review behavior while using "Include group memberships that are entitlements of their assigned global roles"… 39Number of Views Imported business descriptions are not updated correctly for groups in different applications having the same name in RSA … 46Number of Views How to Synchronize Nested AD Group Users from an RSA SecurID Access Identity Source 150Number of Views RSA PAM Authentication Agent cannot challenge users in Active Directory groups 276Number of Views Entitlements manually added when an Application has 'Complete Manual Activity Before Collection' enabled are not removed w… 128Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?