Is it required to refresh LDAP users groups in PAM ?
search cancel

Is it required to refresh LDAP users groups in PAM ?

book

Article ID: 117663

calendar_today

Updated On:

Products

CA Privileged Access Manager - Cloakware Password Authority (PA) CA Privileged Access Manager (PAM)

Issue/Introduction

If a PAM user has policies configured and belongs to an LDAP group, but later is removed from this LDAP group on the LDAP/AD server side, will he still succeed to use the target devices based on the unchanged user group policies?

Resolution

When PAM imports an LDAP group, it creates entries for each user in the PAM database and assigns group membership at the time of import. As long as the LDAP group is not refreshed in PAM after modifications in the LDAP server, nothing will change from a PAM perspective and the PAM user will retain group memberships and associated access policies.

Once you refresh an LDAP group in PAM:
If the user left the LDAP group and is not a member of any other imported group, PAM will delete the user entry and the user will no longer be able to access PAM at all.

If the user left the LDAP group, but still is member of other user groups imported into PAM, then the access policies for that group will no longer be available to this user, but he still can access PAM and use all the policies associated with the remaining group memberships, or policies defined for the user directly.

If the user remains in the same LDAP group but changed its OU only, the group policies remain intact for the user.

Note:
In addition to the explicit manual refresh of the LDAP group using the PAM UI, the LDAP group also auto-refreshes based on the sync schedule you configured for this LDAP domain under Configuration > 3rd Party > LDAP. 

Additional Information

Please see also

Import LDAP User Groups

How to Set Up LDAP Servers for User Authentication