1) Verify in CloudSOC that the msDS-PrincipalName attribute is being used to populate the Secondary ID for users.
- Go to Settings -> CloudSOC SpanVA -> SpanVA Secondary User Attribute. Set the drop down to msDS-PrincipalName
2) Verify the user has the correct value for their Secondary ID in the msDS-PrincipalName attribute for their user in AD.
- View the user through Active Directory Users and Computers. View the Attribute Editor tab on the user.
- Verify the ADSync User account has access to view the msDS-PrincipalName attribute. A good way to do this is to use a 3rd party LDAP browser such as Softerra.
- The AD Sync User account should have Administrative privileges, or permissions on the directory tree set in the Base DN on the ADSync profile.