Modifying Group Membership in an LDAP Directory
Last Modified: 2026-08-25
Modifying Group Membership in an LDAP Directory
In order to optimize performance and minimize traffic between AM and an LDAP directory, AM caches information about user group memberships. When a user’s group membership is changed in an LDAP directory, AM cannot acknowledge the change until the cache is refreshed. As a result, these changes take effect after the cache refresh interval has elapsed. In the time between the change and the refresh, you may see the following behaviors:
- A user added to a group that has access to a restricted agent cannot authenticate to the restricted agent.
- A user who has been removed from a group that has access to a restricted agent can still authenticate to the agent.
You can flush the cache immediately using the Operations Console. For more information, see Flush the Cache.
For more information on configuring the cache, see Configure the Cache.
Related Articles
Modifying a User in an LDAP Directory 8Number of Views Moving Users in an LDAP Directory 36Number of Views When Active Directory is integrated using Winbind, group membership for Active Directory users fails with the RSA Authenti… 170Number of Views IDR SSO - Step 5: Connect LDAP Directory 114Number of Views Authentication Manager LDAP Connection Fails with "One or More Directory Connections Is Incorrect" 1.99KNumber of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?