No users of groups visible when configuring a UNAB policy in PAM
search cancel

No users of groups visible when configuring a UNAB policy in PAM

book

Article ID: 393366

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Configuring a Linux Endpoint with PAM SC and UNAB, the endpoint is visible in PAM and it can communicate correctly with the Distribution host

However when trying to configure a UNAB policy, no users or groups are available for that endpoint 

The endpoint can successfully communicate with Active Directory as show by issuing an uxconsole command

But then in PAM, when adding a UNAB policy, no users or groups are available

Cause

To be able to do the UNAB integration with PAM there are several steps. Besides importing the AD users into PAM, they need to have the necessary UNIX attributes, which require configuration as specified in the documentation for using AD users with UNAB.

Now those attributes must be present in AD already when importing the users to PAM in order for it to understand that they are eligible to work with UNAB in PAM. If these users were already imported without the UNIX attributes present in AD they will not be recognized.

Resolution

Please refresh the LDAP groups which were already imported into PAM and which should be used for UNAB endpoints in order for the product to pick up their UNIX attributes and thus make them available to UNAB