Issue with Before Provisioning Rule and ObjectNotFoundException during User Leaver Process

Hi @vguleria the below events took place for disable account operation.

Modify Account Passed
Remove Entitlement Passed
Change Identity State Passed
Disable Account Failed

Looks like there is some uppercase or lowercase issue in the DN and does it cause any issue in triggering the leaver operation?

Thanks
Kalyan

1 Like

@kalyannambi2010

Thank you for sharing the details. I am not sure if uppercase of lowercase will cause an issue but i had seen issue where this casing difference was showing me warnings, so probably it could be the issue.

Can you please try to make sure that new ac parent value is exactly the same without the differences between uppercase and lowercase and then try to trigger the operation.

Please let me know the outcome, i hope it works.

Thank you.
Regards
Vikas.

1 Like

Hi @vguleria thank you and already we have set “AC_NewParent” without the differences between uppercase and lowercase.

Thanks
Kalyan

1 Like

Hi @kalyannambi2010

Do you still see the error ?

Thank You.
Regards
Vikas.

1 Like

Hi @vguleria, yes we are still getting the error and already we have set “AC_NewParent” without the differences between uppercase and lowercase long time ago.

Thanks
Kalyan

1 Like

Hi @kalyannambi2010,

I think then it would be wiser to check the issue with sailPoint support team. They can access the logs generated by the cloud rule and then should be able you further.

Unfortunately, i can not think of anything else here which might have caused an issue. Perhaps, May be a last attempt when i checked the error message again , it is trying to update the user
CN=Test,OU=Departed,OU=User Accounts,DC=Test,DC=Test,DC=com

Not sure but you can double check DC=Test,DC=Test if this is correct. But having said that i believe you can have a look at the issue with support team and they should be able to access the logs and provide you the proper resolutions.

Good luck with resolving the error.

Thank You
Kind regards
Vikas.

1 Like

@kalyannambi2010 how are you?

Try doing thing in two steps, first Move the account and create a lifecycleState just for that. This will trigger the Native Change and update the link on IDN. Them create the Leaverr/terminated state to do the other operations.

is not the best, but it works.

1 Like

Hi @vguleria thank you so much for your inputs.

Thanks
Kalyan

1 Like

I am also facing same issue. We are updating AC_newParent attribute through before Provisioning rule, account is getting updated in AD properly. but we are getting sailpoint.connector.ObjectNotFoundException exception in events.

Please let me know the solution if you are able to resolve this issue.

Hi everyone,

Still we are facing the issue and please let me know the solution if you are able to resolve this issue.

Thanks
Kalyan

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.