Modifying Group Membership in an LDAP Directory
Modifying Group Membership in an LDAP Directory
In order to optimize performance and minimize traffic between AM and an LDAP directory, AM caches information about user group memberships. When a user’s group membership is changed in an LDAP directory, AM cannot acknowledge the change until the cache is refreshed. As a result, these changes take effect after the cache refresh interval has elapsed. In the time between the change and the refresh, you may see the following behaviors:
- A user added to a group that has access to a restricted agent cannot authenticate to the restricted agent.
- A user who has been removed from a group that has access to a restricted agent can still authenticate to the agent.
You can flush the cache immediately using the Operations Console. For more information, see Flush the Cache.
For more information on configuring the cache, see Configure the Cache.
Related Articles
CSV Format for User Group Membership Requests Input File 8Number of Views Change in the review behavior while using "Include group memberships that are entitlements of their assigned global roles"… 36Number of Views View User Group Memberships for a User in the User Dashboard 18Number of Views List User Group Membership in Reports 30Number of Views Role membership rules configured in the RSA Identity Governance & Lifecycle's Role UI do not create rules when no checkbox… 49Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 Troubleshooting RSA MFA Agent for Microsoft Windows How to download and install the AFX Server Archive in RSA Identity Governance & Lifecycle The Template ({Connector Template Name}) has missing file content error when creating AFX Connectors in RSA Identity Gover…
Don't see what you're looking for?