When using the userAccountControl attribute in the Account Search Filter of the Account Data Collector definition for Active Directory and LDAP Account Data Collectors in RSA Identity Governance & Lifecycle, the following error occurs when testing the filter:
javax.naming.directory.InvalidSearchFilerException:Unbalanced parenthesis; remaning name 'OU=vcloud Users,DC=2k8r2-vcloud,DC=local'
The syntax is incorrect.
The userAccountControl Attribute requires an extra set of parentheses surrounding it. These are showin below in red.
Modify the reference to the userAccountControl attribute in the Account Search Filter definition:
Change from (!userAccountControl:1.2.8126.96.36.199.802:=2)
Change to (!(userAccountControl:1.2.8188.8.131.52.802:=2))
Note the extra set of parentheses that are required after the exclamation point and the attribute name, and also to end the string.