AD account collector is not collecting the Last Login Date and Expiration Date in RSA Identity Governance and Lifecycle 7.0.2
Originally Published: 2019-02-11
Article Number
Applies To
RSA Product/Service Type: Appliance
RSA Version/Condition: 7.0.x
Issue
Cause
These mapped attributes are actually the column names in accounts table as shown below:
While configuring the mappings for above two columns, respective attributes from Active Directory should be used. The correct configuration is shown in Resolution section below.
Resolution
'accountExpires' and 'lastLogOn' AD attributes to map to the respective attributes 'Expiration Date' and 'Last Login Date'.
In RSA Identity Governance and Lifecycle 7.0.1 and 7.0.2 P01 to P04 versions, the LAST_LOGIN_DATE attribute collects 'lastLogOn' attribute of accounts from AD and this is internal mapping, these two attributes are not configurable in GUI.
However, from RSA Identity Governance and Lifecycle 7.0.2 P05 and onwards, LAST_LOGIN_DATE attribute has been made configurable on collector UI and its mapping can be modified as per requirement. Also this attribute configuration is optional.
The default mapping that we provide for this attribute is 'LastLogon' attribute from Active Directory.
LastLogon:
When a user logs on, this attribute is updated on the Domain Controller that provided the authentication ONLY. Because it is only updated on one DC, that means this attribute is not replicated.
For reference:
https://social.technet.microsoft.com/wiki/contents/articles/22461.understanding-the-ad-account-attributes-lastlogon-lastlogontimestamp-and-lastlogondate.aspx
After correcting the mapping, both attribute values are collected correctly as shown below:
Workaround
You can use 'LastLogonTimeStamp' by collecting it in a custom attribute of type "Date" and in the ADC , we can map the custom attribute to lastLogontimeStamp and run the collection. In the Raw data collected , you can verify that the attribute is collected properly and shown in Date format.
Related Articles
Programatically create a user with no expiration date in RSA Authentication Manager 8.x 22Number of Views RSA Authenticator Utility does not import digital certificate which has an expiration date of 2/3/2106 28Number of Views In RSA Identity Governance & Lifecycle, what is the difference between an account's Last Collected Date and Last Collected… 34Number of Views RSA Identity Governance and Lifecycle IBM Lotus Notes (Domino) collector does not collect group data. 50Number of Views How to collect data from an RSA Authentication Agent 7.x for Windows for troubleshooting 242Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Unable to login to RSA Authentication Manager Security Console as super admin RSA Release Notes for RSA Authentication Manager 8.8
Don't see what you're looking for?