Failing to delete an LDAP user in PAM via LDAP refresh
search cancel

Failing to delete an LDAP user in PAM via LDAP refresh

book

Article ID: 248745

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

After removing a user from AD and performing an LDAP group refresh in CA PAM, the user is not deleted.

To remediate this issue, Broadcom-provided PAM_USR_SYNC was applied, but patch application results in the following error in Session Log, and the user is still not deleted:

"Unable to delete user <user CN> because it has custom report <CUSTOM-REPORT-NAME> assigned. Please delete the report and run the patch again."

Cause

PAM Session Log indicates that the user for which deletion is being attempted is associated with customized report(s) and therefore cannot be deleted from PAM. 

Resolution

1. Delete the custom reports associated with this user which are mentioned in the PAM Session Log by going to (Session==>Logs==>Reports===>Manage Reports)

2. Please apply PAM_USR_SYNC  patch again and as a result user should be successfully removed showing the success message  in the Session Log:

     User <brokenuser@brokenuserdomain> was present in the access manager but not the credential manager. deleting.


Additional Information

To request the latest version of