When resetting an out of band (OOB) account password, Access Fulfillment Express (AFX) will always look for full DN to search accounts in RSA Identity Governance and Lifecycle
Originally Published: 2016-05-27
Article Number
Applies To
RSA Product/Service Type: All
Issue
AFX reports this item failed with code [-1] and message: 'org.mule.api.transformer.TransformerMessagingException:
Search for attributes for CN=jdoe,OU=Test_User,DC=2k8r2-vcloud,DC=local returned empty. The entry may not exist.
Aborting request! (java.lang.IllegalArgumentException) (org.mule.api.transformer.TransformerException).
Message payload is of type: String'. If available, another handler will be used to fulfill this item.
Below error seen in comment box :
Cause
The DN for the test user John Doe is CN= John Doe ,OU=Test_User,DC=2k8r2-vcloud,DC=local. If the account is a sAMAccountName (e. g., jdoe) then AFX tries to search the DN as CN=jdoe,OU=Test_User,DC=2k8r2-vcloud,DC=local. Since it does not find this DN in Active directory, it displays the error.
Resolution
The connector will always try to look up an account or group using the DN.
This doesn't mean that you need to collect accounts with Account ID set to DN. What it does mean is that you need to collect either the account CN or DN as an attribute and map that attribute to the account parameter on the Reset an Account's Password tab and for any other account-related command EXCEPT for Create Account. It is most likely that not all of your accounts are in the same OU, so you would want to collect and map the full DN to the account parameter.
If, however, all the accounts are in the same OU structure and the CN is made up of attributes from associated user object(s), then the account parameter for the Reset Password command can be mapped to those user attributes. An example of this would be if your CN looks like CN = $User.First_Name $User.Last_Name. For the account parameter to Reset an Account's Password in the connector, the attribute mapping would look like $User.First_Name $User.Last_Name.
Related Articles
RSA Authenticator 4.3 for iOS and Android Coming in August 2023 with New Look and More 32Number of Views In RSA Identity Governance & Lifecycle, when a user looks at a role in a role review that is on hold and presses OK instea… 19Number of Views Java client looks for a new key when requested stale key is in the cache 20Number of Views SA Looking for Live Manager Thick client in order to down load packages for off external Network SA Servers 5Number of Views A user sees an empty screen when looking at review items in RSA Identity Governance & Lifecycle 18Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?