Active Directory Account Data Collector (ADC) incorrectly collects null value for PwdLastSet as date 9999-12-31 in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-04
Article Number
Applies To
RSA Version/Condition: 7.1.0, 7.1.1
Issue
If the PwdLastSet attribute in Microsoft Active Directory (AD) is null, RSA Identity Governance & Lifecycle's AD Account Data Collector (ADC) incorrectly collects the value as the date 9999-12-31 with a time value that represents the time of the last collection.
For example, the PwdLastSet attribute may be collected as 9999-12-31 12:45:50. Since the time portion of the attribute may change between subsequent collections, this may incorrectly cause the Account to be marked as Changed even though there was no change to the collected values.
Cause
This is a known issue reported in engineering ticket ACM-92309.
Resolution
- RSA Identity Governance & Lifecycle 7.1.0 P07
- RSA Identity Governance & Lifecycle 7.1.1 P02
- RSA Identity Governance & Lifecycle 7.2
Notes
Related Articles
Duplicate User IDs 96Number of Views upgrade adds geoip_SHORTRUN_1.dat 18Number of Views Maintain Authentication Agent Associations in a Duplicated User Group 13Number of Views Duplicate entitlements are created when an Application has 'Complete Manual Activity Before Collection' enabled in RSA Ide… 116Number of Views Workaround to remove duplicate identities resulted to mapping of account to a terminated account instead of the active one 77Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide How to Download OTP Token Seed Files from myRSA Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio…
Don't see what you're looking for?