AD MemberOf Attribute Name is same as DN name

Hi,

We noticed that during entitlement aggregation for AD, AD groups those dont have name or displayname assigned takes the DN value as its name. Is it the expected behavior from sailpoint?

Eg :
Usual case where display name is assigned in AD

In IDN:

Name : ADGrp1 , Display Name : ADGrp1 and Value : CN=ADGrp1,ou=group,dc=abcd,dc=com

Case where display name is empty in AD

In IDN:

Name : CN=ADGrp1,ou=group,dc=abcd,dc=com,
Display Name : CN=ADGrp1,ou=group,dc=abcd,dc=com
Value : CN=ADGrp1,ou=group,dc=abcd,dc=com

Thanks

Hi, it looks like it’s only bringing in the group DN your AD account holds. That is usually the case when that group is outside the defined “group search scope”. Check your source configuration page and verify the group search scope. Then, try running the entitlement aggregation again. Hope this helps!

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.