Hi Team,
I require your assistance in the issue with the Active Directory (AD) group rename or OU change in target application.
IdentityIQ version: IIQ 8.4p1
Application: Microsoft Active Directory
objectType: group
identity Attribute: distinguishedName(DN)
Issue happens when somebody changes below directly in target application:
- Rename a group
- Change the OU
Issue is replicated upon next AD group Aggregation in IIQ:
- Existing entitlement in Entitlement catalogue is replaced with new entitlement and thus all its existing properties are lost like requestable, owner, etc.
- name change or OU change of the group does not replicate in the the existing IT role in which old entitlement was already a member.
Solution Implemented till now:
-
Already enabled the below in gear icon > Global Settings > IdentityIQ Configuration > Miscellaneous tab:
Enable Native Identity Change Event propagation -
Request Definition Object: Native Identity Change Propagation Request looks like below:
Which IIQ version are you inquiring about?
8.4 p1*
Please share any images or screenshots, if relevant.
Please share any other relevant files that may be required (for example, logs).
[Please insert files here, otherwise delete this section]
Share all details about your problem, including any error messages you may have received.
Old entitlement is replaced with new when next AD group aggregation happens
AD group name is not replicated in the role
When somebody is assigned the role, then the assignment fails with below error:
“Error(s) reported back from the IQService - Error occurred while connecting to group CN=TEST_IAM_New_Updated_17Jan,OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local. Failed to connect to the server for CN=TEST_IAM_New_Updated_17Jan,OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local:There is no such object on the server. There is no such object on the server. 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of: ‘OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local’ 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of: ‘OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local’ . HRESULT:[0x80072030]Failed to connect to the server for CN=TEST_IAM_New_Updated_17Jan,OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local:There is no such object on the server. There is no such object on the server. 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of: ‘OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local’ 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of: ‘OU=TEST,OU=FileGroups,OU=----,DC=-----test,DC=local’ . HRESULT:[0x80072030] Possible reasons for failure include a) The Domain Controller is currently not reachable b) The object has either been moved or renamed c) The object has been deleted Please Ensure the data has been aggregated before performing the operation”.
Would appreciate your assistance on same.
Please suggest how can we make the group rename and OU change work without impacting the existing entitlement in IIQ.
Thanks & regards,
Ankur