Error: PAM-CMN-0234 and PAM-CM-0728 during LDAP Group Refresh in CA Privileged Access Manager
search cancel

Error: PAM-CMN-0234 and PAM-CM-0728 during LDAP Group Refresh in CA Privileged Access Manager

book

Article ID: 454392

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

This article addresses LDAP group refresh failures in CA Privileged Access Manager (PAM) resulting in error codes PAM-CMN-0234, PAM-CMN-2277, or PAM-CM-0728. 

Environment

  • Product: PAM all versions
  • Target: Windows Active Directory

Cause

These errors can occur when a user account in Active Directory (AD) contains an invalid email address format.

Resolution

  1. Identify the user(s) causing the failure by reviewing the PAM session logs. Look for the error: PAM-CM-0728: User email address is invalid.
  2. Access the user's account properties in Active Directory.
  3. Validate the email address format. Ensure there are no invalid characters (e.g., a comma instead of a dot, or multiple "@" symbols).
  4. Correct the email address in Active Directory to a valid format.
  5. In PAM, navigate to the LDAP group refresh settings and initiate a manual refresh.
  6. Verify that the LDAP group refresh completes successfully.

If the issue persists, ensure that no other user attributes are causing conflicts. If you require further assistance, please contact our Support team.