Sub-groups resolution is rejected and Member Type is set to "Account" instead of "Group" for Account Collectors in RSA Identity Governance and Lifecycle
Originally Published: 2017-10-03
Article Number
Applies To
RSA Version/Condition: 6.9.1 P15- P19, 7.0.0 P04, 7.0.1
Issue
In the following example, we are using groups and sub-groups collected from Active Directory.
1. We have two groups in AD as below
2.Sub-Group is the member of Top-Group.
3. Account Collector with the below configuration for the groups.
4. Following is the subgroup resolution.
5. Collect data, then check the monitoring >> raw data >> Group Membership tab, you will find that the Top-Group to Sub-Group resolution is failing and the Sub-Group is collected as an "Account", not as a "group":
Cause
For version 7.0.0 and 7.0.1 this is fixed in 7.0.0 P05 and 7.0.1 P02 respectively.
Resolution
Related Articles
Objects previously collected by Account Collectors and Entitlement Collectors in 6.x are rejected in 7.x of RSA Identity G… 158Number of Views Data Access Collector (DAC) rejects Account Relationships when collecting Account Permissions in RSA Identity Governance &… 147Number of Views Oracle bug ORA-00600 ktecgsc:objdchk_kcbgcur_3 causing the collectors to fail 53Number of Views RSA Governance & Lifecycle Recipes: Report - AD Admin Group Members 30Number of Views Acesyncd not shutting down on Replica when ACE/Server is shut down; acesyncd process continues to run for several minutes 27Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio… Deploying RSA Authenticator 6.2.2 for Windows Using DISM Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?