How a User Becomes Unresolvable
Changes made to user data in an LDAP directory can affect authentication and administration of the user when the change in the directory modifies the user’s distinguished name (DN), the user’s User ID, or both. If a user’s DN or User ID is changed, AM can no longer find the user in the LDAP directory that was designated as his or her identity source. A user (or a user group) in this state is known as “unresolvable.” RSA recommends removing references to unresolvable users and user groups because unresolvable users count against the license user limit if they have assigned authenticators.
A user becomes unresolvable for any of the following reasons:
The user is deleted from the LDAP directory.
The user is moved outside the scope of the base DN of the identity source.
The user is moved outside the scope of all identity sources.
The scope of the identity source is narrowed so that it no longer includes the user.
The Search Filter of the identity source is modified so that it no longer contains the user.
The user is moved to an identity source in the same physical directory using the delete and add method, and the Unique Identifier is configured to use the default value.
The user is moved to an identity source in a different physical directory.
Users who become unresolvable are reported as missing from the identity source.
After cleaning up users who have been moved to a different identity source, you re-establish these users in AM by enabling them for authentication, or assigning them administrative roles.
Some directory management tools move users by deleting and re-adding them to the directory. In these cases, AM cannot find the users after the move when the default Unique Identifier is used. Deleting and adding the user back to the directory creates a new value for ObjectGUID, the default Unique Identifier. To maintain the same value for your users, configure a customized attribute as the Unique Identifier.
Related Articles
Manual Cleanup for Unresolvable Users 52Number of Views Scheduling Cleanup for Unresolvable Users and User Groups 76Number of Views FIM Error cleaning up temporary users 4Number of Views Hide or Show Agent Information in the User Dashboard on RSA Authentication Manager 8.6 P1 and up 15Number of Views Edit a Security Domain 7Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide