Sub-groups resolution is rejected and Member Type is set to "Account" instead of "Group" for Account Collectors in RSA Identity Governance and Lifecycle
Originally Published: 2017-10-03
Article Number
Applies To
RSA Version/Condition: 6.9.1 P15- P19, 7.0.0 P04, 7.0.1
Issue
In the following example, we are using groups and sub-groups collected from Active Directory.
1. We have two groups in AD as below
2.Sub-Group is the member of Top-Group.
3. Account Collector with the below configuration for the groups.
4. Following is the subgroup resolution.
5. Collect data, then check the monitoring >> raw data >> Group Membership tab, you will find that the Top-Group to Sub-Group resolution is failing and the Sub-Group is collected as an "Account", not as a "group":
Cause
For version 7.0.0 and 7.0.1 this is fixed in 7.0.0 P05 and 7.0.1 P02 respectively.
Resolution
Related Articles
Objects previously collected by Account Collectors and Entitlement Collectors in 6.x are rejected in 7.x of RSA Identity G… 159Number of Views Can I have different analytic servers on the same network connecting to same SilverTap in RSA Web Threat Detection 6.1 7Number of Views The review "Include sub-groups" option does not include sub-groups in the review in RSA Identity Governance and Lifecycle 31Number of Views Sub menu buttons defined in drop-down request buttons may have truncated text in RSA Identity Governance & Lifecycle 19Number of Views Creating a user password that does not expire. 10Number of Views
Trending Articles
How a Multi-App Entitlement Collector (MAEDC) resolves entitlement relationships with accounts and groups collected by a M… RSA Governance & Lifecycle 8.0 Patch 10 Release Notes RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows User Event Monitor Messages for Cloud Access Service (20601 - 38000) Authentication context not added / Context validation failed errors authenticating with RSA Authentication MFA Agent for A…
Don't see what you're looking for?