When attempting to import a new Active Directory group using Microsoft Active Directory Import, it does not add the accounts to the role
search cancel

When attempting to import a new Active Directory group using Microsoft Active Directory Import, it does not add the accounts to the role

book

Article ID: 436935

calendar_today

Updated On:

Products

IT Management Suite

Issue/Introduction

Setup a new Role and Account Microsoft Active Directory (AD) Import rule; however, when this rule runs, it does not bring in the expected AD group. Other rules bring in other groups as expected.

Cause

The Application Identity account had access to read the OUs containing target objects, but did not have access to read the attributes of the actual objects within the Organizational Unit (OU)

Resolution

The customer in this case adjusted the permissions in Active Directory to allow the Application Identity account to read the attributes of the objects in the target OU.