How to exclude RSA Authentication Manager 8.x from picking up disabled user account data from the Microsoft LDAP directory
Originally Published: 2018-06-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
Resolution
- Login to the Operations Console of the primary Authentication Manager instance.
- Click Deployment Configuration > Identity Sources > Manage Existing.
- When prompted, enter the super admin user ID and password
- Click the context arrow for the identity source in question and select Edit.
- Click the Connection(s) tab or the Map tab to view the properties of the external identity source:
- Scroll down to the Directory Configuration - Users section and modify the default search filter from (&(objectClass=User)(objectcategory=person)) to the string below:
(&(objectClass=User)(objectcategory=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
- Once done, click Save and Finish for the changes to take effect.
- Login to the Security Console for the primary.
- Verify that the disabled user accounts from the Microsoft LDAP Directory are filtered.
Notes
For steps on how to create a new identity source, please see article Add an Identity Source.
Related Articles
IDR SSO - Step 5: Connect LDAP Directory 113Number of Views How to Include or Exclude an Active Directory OU from the Microsoft LDAP directory on RSA Authentication Manager 8.x 103Number of Views How to test access to Active Directory and LDAP endpoints using 'ldapsearch' in RSA Identity Governance & Lifecycle 509Number of Views Active Directory AFX 'Disable/Enable an Account' connector capabilities do not update added parameters in RSA Identity Gov… 247Number of Views Certificate not verified error when changing Active Directory identity source from LDAP to LDAPS in RSA Authentication Man… 676Number of Views
Trending Articles
How to generate a PASSCODE for manual entry on a Ericsson R380 WAP phone RSA Authentication Manager 8.9 Release Notes (January 2026) IDR SSO - Step 3: Deploy the Identity Router How to enable RSA SecurID protection on Microsoft Outlook Web Access (OWA) Exchange ActiveSync (EAS) and Microsoft Outlo… RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?