The Active Directory Account Data Collector does not have an option to collect Logon Hours in RSA Identity Governance & Lifecycle 7.0.2 and 7.1.x
Originally Published: 2019-05-01
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0
Issue
The Active Directory Account Data Collector does not have an option to collect Logon Hours in RSA Identity Governance & Lifecycle.
There have been unsuccessful attempts to work around this product limitation. For example,
- Modify the LoginHours Attribute in Active Directory. Options to set hours exist for Logon Permitted and Logon Denied time frames.
- Add a LogonHours collected account attribute in the RSA Identity Governance & Lifecycle User Interface, under Admin > Attributes.
- Run an Account Data Collection.
There are two problems with this workaround.
- First, if Logon Denied is chosen and all hours are denied, the collection fails with the following error:
09/12/2018 07:40:45.815 INFO (Exec Task Consumer#0) [com.aveksa.server.xfw.TaskExecutor] Setting thread Thread[Exec Task Consumer#0,5,Execution Queue] on 583384 method=Execute
09/12/2018 07:40:47.206 ERROR (Exec Task Consumer#0) [com.aveksa.server.xfw.SAXAccountDataHandler] Error in processing Account Data
org.xml.sax.SAXParseException; lineNumber: 163501; columnNumber: 142; An invalid XML character (Unicode: 0x0) was found in the value of attribute "logonHours" and element is "attributes".
at org.apache.xerces.util.ErrorHandlerWrapper.createSAXParseException(Unknown Source)
at org.apache.xerces.util.ErrorHandlerWrapper.fatalError(Unknown Source)
at org.apache.xerces.impl.XMLErrorReporter.reportError(Unknown Source)
at org.apache.xerces.impl.XMLErrorReporter.reportError(Unknown Source)
- If any other setting is chosen, the collection succeeds, but the display is in octet format and therefore, unreadable.
Cause
Resolution
Please go to RSA Link RSA Ideas for RSA Identity Governance & Lifecycle to submit and/or vote on an enhancement request. For more information, please see How to log a request for enhancement (RFE) for RSA Identity Governance & Lifecycle.
Related Articles
PersistenceException Error when previewing an RSA Identity Governance & Lifecycle report that has not yet been saved 52Number of Views RSA Via Lifecycle and Governance Salesforce Account Data Collector does not allow configuration without a "Security Token" 93Number of Views Custom attribute field cannot be blank when creating an Active Directory Entitlement Data Collector in RSA Identity Govern… 78Number of Views How to update an Active Directory Account Attribute to have no value <not set> using an Active Directory AFX Connector in … 134Number of Views RSA Identity Management and Governance 6.9.1 P12 Active Directory Identity Data Collector (IDC) collection fails with "Unp… 89Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to Detect and Resolve Stalled Workflows and Workpoint Issues in RSA Identity Governance & Lifecycle How to change the default Oracle Statistics History Retention period for RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Installation Guide Download RSA SecurID Access Cloud Administration audit logs using Cloud Administration REST API CLU
Don't see what you're looking for?