The Active Directory Account Data Collector does not have an option to collect Logon Hours in RSA Identity Governance & Lifecycle 7.0.2 and 7.1.x
Originally Published: 2019-05-01
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0
Issue
The Active Directory Account Data Collector does not have an option to collect Logon Hours in RSA Identity Governance & Lifecycle.
There have been unsuccessful attempts to work around this product limitation. For example,
- Modify the LoginHours Attribute in Active Directory. Options to set hours exist for Logon Permitted and Logon Denied time frames.
- Add a LogonHours collected account attribute in the RSA Identity Governance & Lifecycle User Interface, under Admin > Attributes.
- Run an Account Data Collection.
There are two problems with this workaround.
- First, if Logon Denied is chosen and all hours are denied, the collection fails with the following error:
09/12/2018 07:40:45.815 INFO (Exec Task Consumer#0) [com.aveksa.server.xfw.TaskExecutor] Setting thread Thread[Exec Task Consumer#0,5,Execution Queue] on 583384 method=Execute
09/12/2018 07:40:47.206 ERROR (Exec Task Consumer#0) [com.aveksa.server.xfw.SAXAccountDataHandler] Error in processing Account Data
org.xml.sax.SAXParseException; lineNumber: 163501; columnNumber: 142; An invalid XML character (Unicode: 0x0) was found in the value of attribute "logonHours" and element is "attributes".
at org.apache.xerces.util.ErrorHandlerWrapper.createSAXParseException(Unknown Source)
at org.apache.xerces.util.ErrorHandlerWrapper.fatalError(Unknown Source)
at org.apache.xerces.impl.XMLErrorReporter.reportError(Unknown Source)
at org.apache.xerces.impl.XMLErrorReporter.reportError(Unknown Source)
- If any other setting is chosen, the collection succeeds, but the display is in octet format and therefore, unreadable.
Cause
Resolution
Please go to RSA Link RSA Ideas for RSA Identity Governance & Lifecycle to submit and/or vote on an enhancement request. For more information, please see How to log a request for enhancement (RFE) for RSA Identity Governance & Lifecycle.
Related Articles
Active Directory Account Data Collectors are failing in pre-processing in RSA Identity Governance & Lifecycle 52Number of Views SAP AFX Connector Update an Account capability fails to update any SAP account attributes in RSA Identity Governance & Lif… 97Number of Views Salesforce AFX Connector 'Update an Account' Capability fails to update additional Parameters in RSA Identity Governance &… 80Number of Views Collection Data Pre-Processing takes longer and longer to complete in RSA Identity Governance & Lifecycle 53Number of Views Active Directory AFX Connector Create Account capability fails when skip certificate validation in RSA Identity Governance… 397Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?