What access should be granted to the service account used by RSA Identity Governance & Lifecycle to fully support Active Directory collection and Access Fulfilment Express (AFX) fulfillment?
Originally Published: 2018-05-05
Last Modified: 2026-05-13
Article Number
Applies To
RSA Version/Condition: All
Issue
The RSA Identity Governance & Lifecycle Microsoft Active Directory Application Guide does not explicitly state the access which needs to be granted or delegated to the service account used by RSA Identity Governance & Lifecycle to fully support Active Directory collection and Access Fulfilment Express (AFX) fulfillment to Active Directory.
Find all of the the Collector and Connector datasheets (aka Application Guides) on RSA Link.
Resolution
"Domain Account Name Admin account name to use for the collection and provisioning activities
Login Distinguished Name Administrator login- id with write permission on required tree scope
Bind DN Distinguished Name of the user on AD permitted to search
the directory within the defined search base. E.g.
Domain\Administrator
To configure RSA Identity Governance and Lifecycle ADC to collect data from Domain2 using the Domain1 administrator: "
Hence, the account needs to be an administrator's account which by default has all privileges to fully support Active Directory collection and AFX fulfillment to Active Directory.
Related Articles
Request a Cloud Access Service Account 32Number of Views Does FSM support adding Local System Account to Roles? 1Number of Views When should a Provisioning-Termination Rule delete accounts in RSA Identity Governance & Lifecycle? 198Number of Views Change Items depends on Account Creation marked as 'Rejected' If the Create Account Request 'Cancelled' without showing th… 4Number of Views AveksaAdmin Super Account Locked or Password Lost in RSA Governance & Lifecycle 1.79KNumber of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog RSA Authentication Manager 8.9 Patches and Hotfixes Readme
Don't see what you're looking for?