Sub-groups resolution is rejected and Member Type is set to "Account" instead of "Group" for Account Collectors in RSA Identity Governance and Lifecycle
Originally Published: 2017-10-03
Article Number
Applies To
RSA Version/Condition: 6.9.1 P15- P19, 7.0.0 P04, 7.0.1
Issue
In the following example, we are using groups and sub-groups collected from Active Directory.
1. We have two groups in AD as below
2.Sub-Group is the member of Top-Group.
3. Account Collector with the below configuration for the groups.
4. Following is the subgroup resolution.
5. Collect data, then check the monitoring >> raw data >> Group Membership tab, you will find that the Top-Group to Sub-Group resolution is failing and the Sub-Group is collected as an "Account", not as a "group":
Cause
For version 7.0.0 and 7.0.1 this is fixed in 7.0.0 P05 and 7.0.1 P02 respectively.
Resolution
Related Articles
How to enable a Custom Account Attribute for selection when defining the Account Resolution Rules for an Account Collector… 60Number of Views Objects previously collected by Account Collectors and Entitlement Collectors in 6.x are rejected in 7.x of RSA Identity G… 158Number of Views Partially orphaned accounts occur in RSA Identity Governance & Lifecycle when the ADC defines multiple user resolution att… 70Number of Views Joiner Mover Leaver Change Requests are getting rejected with "object references an unsaved transient instance" error in R… 2Number of Views Data Access Collector (DAC) rejects Account Relationships when collecting Account Permissions in RSA Identity Governance &… 147Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Quick Setup Guide - Connect Authentication Manager to Cloud Authentication Service RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager Patch Updates Downloading RSA Authentication Manager license files or RSA Software token seed records
Don't see what you're looking for?