Troubleshooting
Problem
You have an environment where the Windows Active Directory has groups.
The groups have been created within IBM Security Identity Governance and Intelligence from a synchronisation referring to a base point in the Active Directory.
The Enterprise Connector uses the IBM Security Identity adapter for Windows AD 64-bit.
The WinADAdapter.log file shows errors from the synchronisation that the group cannot be found even though it exists in the Windows Active Directory.
The groups have been created within IBM Security Identity Governance and Intelligence from a synchronisation referring to a base point in the Active Directory.
The Enterprise Connector uses the IBM Security Identity adapter for Windows AD 64-bit.
The WinADAdapter.log file shows errors from the synchronisation that the group cannot be found even though it exists in the Windows Active Directory.
Windows is a registered trademark of the Microsoft Corporation
Symptom
In IBM Security Identity Governance and Intelligence, the Windows AD Enterprise Connector "Trace Level" needs to be set to ON and "DEBUG" enabled in order to capture the "DBG" level messages.
The WinADAdapter.log has the errors where the <GUID> is a unique 32 digit hexadecimal (128-bit) number.
DBG:20/05/21 11:02:48 Thread:000123 Error while fetching the group interface for <GUID>. Error code: 0x8007203a - The server is not operational.
DBG:20/05/21 11:02:48 Thread:000123 Error adding membership to group <GUID>. Group not found
BSE:20/05/21 11:02:48 Thread:000123 Attribute ergroup Condition code 5 (Error setting group memberships)
DBG:20/05/21 11:02:48 Thread:000123 Processing Extended attributes...
DBG:20/05/21 11:02:48 Thread:000123 Error adding membership to group <GUID>. Group not found
BSE:20/05/21 11:02:48 Thread:000123 Attribute ergroup Condition code 5 (Error setting group memberships)
DBG:20/05/21 11:02:48 Thread:000123 Processing Extended attributes...
Even though the group exists the error reports that the group cannot be found.
Document Location
Worldwide
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGHJR","label":"IBM Security Identity Governance and Intelligence"},"ARM Category":[{"code":"a8m0z0000001hi9AAA","label":"Identity Governance \u0026 Intelligence-\u003EAdapters"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Log InLog in to view more of this document
This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.
Was this topic helpful?
Document Information
More support for:
IBM Security Identity Governance and Intelligence
Component:
Identity Governance & Intelligence->Adapters
Software version:
All Version(s)
Document number:
6213280
Modified date:
26 May 2020
UID
ibm16213280
Manage My Notification Subscriptions