Identity Manager: Connector Server (CCS) Active Directory Endpoint Monitoring and Failover Intervals
search cancel

Identity Manager: Connector Server (CCS) Active Directory Endpoint Monitoring and Failover Intervals

book

Article ID: 243372

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

Identity Manager Connector Server (CCS) monitoring behavior for Active Directory (AD) endpoints depends on the failover configuration. Without active provisioning tasks, CCS does not maintain a continuous connection unless specific failover parameters are set. Users may observe that endpoints appear "Not Responding" in the console if these intervals are not aligned with environment needs.

Environment

Identity Manager 14.x & v15

Cause

By default, CCS connects to an AD endpoint only when a provisioning activity is triggered. Continuous monitoring is an optional feature tied to the failover mechanism.

Resolution

The monitoring behavior is determined by the following configuration states:

  • Active Directory Failover Enabled:

    • CCS monitors endpoint responsiveness at regular intervals.
    • Default Interval: 15 minutes.
    • Configuration: This is controlled by the ADS_RETRY environment variable.
  • Active Directory Failover Disabled:

    • CCS does not perform regular heartbeat checks or monitoring calls.
    • Trigger: A connection to the AD endpoint occurs only when a provisioning activity (e.g., user creation, attribute update) is executed.

Steps to Verify or Adjust Monitoring:

  1. Access the Active Directory Failover Setup in the Management Console.
  2. If continuous monitoring is required for high availability, ensure failover is enabled.
  3. To modify the monitoring frequency, adjust the ADS_RETRY environment variable on the CCS host machine.