Incomplete Collection of AD Groups in RSA Identity Governance & Lifecycle
Originally Published: 2018-01-17
Article Number
Applies To
RSA Version/Condition: 7.0.1, 7.0.2
Issue
Group Base DN: DC=CompanyXYZ, DC=com
The search criteria is
(&(objectCategory=Group)(objectClass=group))
The Test button for Group Data in the collector edit screen may indicate that the first 1000 is found.
The Test button may on occasion show a timeout which is not recorded in the aveksaServer.log
Upon collection, only a handful of AD administrative groups show up in the raw data for the collection.
Cause
Because of the referral, you will end up in other parts of the tree for which the account you are using has no access rights, hence you collect less or even nothing.
Resolution
In the collector definition, please make sure that you check the Ignore Referrals box.
This will allow the Collector to find and pull in all groups in the domain.
We also suggest that you use a more targeted entry point in the tree, so that ACM collections do not search unnecessarily large areas.
Related Articles
RSA Governance & Lifecycle Recipes: Report - AD Group Summary 15Number of Views RSA Governance & Lifecycle Recipes: Chart - AD Group Summary 15Number of Views Close an Active User Session 17Number of Views RSA Governance & Lifecycle Recipes: Chart - AD Admin Groups 22Number of Views RSA Governance & Lifecycle Recipes: Report - AD Admin Group Members 31Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?