Wrong user id reported in Investigate
search cancel

Wrong user id reported in Investigate

book

Article ID: 248942

calendar_today

Updated On:

Products

CASB Gateway CASB Gateway Advanced CASB Security Premium CASB Security Standard

Issue/Introduction

Investigate detects invalid login

Login is attributed to the wrong user

Environment

CASB/Cloudsoc Gatelet Deployment , Endpoints routes the traffic using the "WSS Agent"

Cause

The main cause of the issue is the "Duplicate secondary IDs".

Cloudsoc enforces the uniqueness on the primary user id, though the condition is relaxed on the secondary user id, where multiple user accounts can share the same secondary id.

for example: [email protected]  and [email protected] can both have the secondary user id set to DOMAIN\USER

 

Resolution

In case where multiple user accounts share the same secondary ID, the mapping process returns the first matching account, which may lead to reporting inconsistencies.

To prevent this issue, each Cloudsoc user must have a unique secondary ID.