Cannot find imported LDAP Group in PAM
search cancel

Cannot find imported LDAP Group in PAM

book

Article ID: 232355

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

When a PAM Admin integrates PAM into Active Directory and imports an Organizational Unit successfully, we cannot find the subsequent imported group in the PAM UI.

Environment

Release : 3.4.x and 4.0.x

Component : PRIVILEGED ACCESS MANAGEMENT

Cause

Organizational Unit do not contain a CN (Common Name)

Resolution

The reason why this happens when importing, our solution looks for a CN (Common Name), if not found, we dynamically create one.

Example:  OU=Admin,OU=Users,DC=example,DC=com
when importing this into PAM, we will list it under "User Groups" as "[email protected]".  

A Traditional Group defined as:

CN=PAM_Admin_Group,OU=USERS,DC=example,DC=com
when importing this into PAM, we will list it under "User Groups" as "[email protected]