The Active Directory Account Data Collector does not have an option to collect Logon Hours in RSA Identity Governance & Lifecycle 7.0.2 and 7.1.x
Originally Published: 2019-05-01
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0
Issue
The Active Directory Account Data Collector does not have an option to collect Logon Hours in RSA Identity Governance & Lifecycle.
There have been unsuccessful attempts to work around this product limitation. For example,
- Modify the LoginHours Attribute in Active Directory. Options to set hours exist for Logon Permitted and Logon Denied time frames.
- Add a LogonHours collected account attribute in the RSA Identity Governance & Lifecycle User Interface, under Admin > Attributes.
- Run an Account Data Collection.
There are two problems with this workaround.
- First, if Logon Denied is chosen and all hours are denied, the collection fails with the following error:
09/12/2018 07:40:45.815 INFO (Exec Task Consumer#0) [com.aveksa.server.xfw.TaskExecutor] Setting thread Thread[Exec Task Consumer#0,5,Execution Queue] on 583384 method=Execute
09/12/2018 07:40:47.206 ERROR (Exec Task Consumer#0) [com.aveksa.server.xfw.SAXAccountDataHandler] Error in processing Account Data
org.xml.sax.SAXParseException; lineNumber: 163501; columnNumber: 142; An invalid XML character (Unicode: 0x0) was found in the value of attribute "logonHours" and element is "attributes".
at org.apache.xerces.util.ErrorHandlerWrapper.createSAXParseException(Unknown Source)
at org.apache.xerces.util.ErrorHandlerWrapper.fatalError(Unknown Source)
at org.apache.xerces.impl.XMLErrorReporter.reportError(Unknown Source)
at org.apache.xerces.impl.XMLErrorReporter.reportError(Unknown Source)
- If any other setting is chosen, the collection succeeds, but the display is in octet format and therefore, unreadable.
Cause
Resolution
Please go to RSA Link RSA Ideas for RSA Identity Governance & Lifecycle to submit and/or vote on an enhancement request. For more information, please see How to log a request for enhancement (RFE) for RSA Identity Governance & Lifecycle.
Related Articles
PersistenceException Error when previewing an RSA Identity Governance & Lifecycle report that has not yet been saved 52Number of Views RSA Authentication Manager 8.7 SP1 Patch 3 Hotfix 1 Readme 62Number of Views How to update an Active Directory Account Attribute to have no value <not set> using an Active Directory AFX Connector in … 133Number of Views Connection failure with certificate issue due to empty TrustStore in RSA Governance & Lifecycle 42Number of Views RSA Via Lifecycle and Governance Salesforce Account Data Collector does not allow configuration without a "Security Token" 92Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA SecurID Software Token 5.0.3 for Microsoft Windows Release Notes How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide
Don't see what you're looking for?