Unable to create an account in Active Directory with a custom objectClass in RSA Governance & Lifecycle
a year ago
Originally Published: 2024-11-25
Article Number
000073053
Applies To

RSA Product Set: RSA Governance & Lifecycle
RSA Version/Condition: 8.0 GA- P04 (inclusive)

Issue

Upon using the "Create an Account capability" in the Active Directory AFX Connector, the account is being created with ObjectClass = 'user' every time. 

The Account is successfully created, with a success message on the Aveksa GUI and appears in the Active Directory.

Modifying the "LDAP object classes to create account" under "Object Creation" in the Connector settings page, allows the account to be created on the Active directory, but it does not modify the ObjectClass for the created account.

The account is created and doesn't have the customized ObjectClass, it will only hold the default ObjectClass settings.

 

Cause

The LDAP connectors previously did not support customizable object classes. This limitation has been addressed, allowing the use of custom object classes for creating accounts and groups.

Resolution

This issue is resolved in the following versions:

  • RSA Governance & Lifecycle 8.0.0 P05 and later versions/ patches.