This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Default AD group is not assigning to new users

I have 5 location based AD attribute and i connected all these to particular location.When a new user came under that location they will get that Groups.

But unfortunately one DA group is not coming under identity .All other groups are assigning properly. I did not find any problem with that group.

How can i check this error.This problem hovering me all the time.Please help me to resolve it.

Parents Reply Children
  • Yes .RIght .There is no Outstanding object.All groups are coming under same forest.i checked that we did not use Categories and group exclusion.Some times all 5 groups will come to user properly.But some times they wont come .That is the issue.Is there any task responsible for assigning default AD group?

  • What do you mean by 

    But some times they wont come

    Do you see that with the same test user, some they are applied and sometimes not? Do you use different users/persons for testing?

    As you have assigned the AD Groups to a location, the task that is responsible for assigning the groups is the DB Queue Processor.

    Did you check the DialogJournal for errors?

  • if there are 10 user ,i created 5 default AD group according to location,every user will get 4 default group among 5 .But one group is always not assigning them properly.sometimes only 2 user get this last AD group.There is some problem with this last AD group.I checked the log file but i could not find any AD group assigning logs. I just want to know is there any process running behind for assigning default AD .Then i can check the issue related to that .Please give me your views.

  • As you have assigned the AD Groups to a location, the task that is responsible for assigning the groups is the DB Queue Processor.
    Did you check the DialogJournal for errors?

    Are the groups assigned insider OneIM but not in the AD only or are the memberships missing in OneIM as well?

  • I checked the DialogJournal but could not find anything.No.In OneIdm also AD groups are not assigning nor the AD also.Membership is missing in OneIdm also.All other groups a are assigning in OneIDm properly except this one AD group.

  • Last option before I suggest contacting support.

    Can you please post the complete screenshot of the ADGroup in ObjectBrowser?

  • in DialogueJournal i could see some errors in "DBQueue Processor".But i could not find anyother description.Just Task name only

  • Hello,

    Like Markus, I, too, am curious to see what the AD Group looks like in Object Browser:

    1. Open Object Browser

    2. Select the table "ADSGroup"

    3. Search for, and locate the AD Group that won't assign

    4. Double click, and screenshot the details

    Also, could you share screenshots of a working, and non-working location from Manager so we can see the configuration?

    Thank you,

    -Roman

  • I can see for setting up deafult AD groups for different location under Manager tool ->Organusations ->Location -> select anyparent location ,there is Table box consist of "IT Configuration setting " and when i open the box i could see "IT Operating data and its value " like  "ADSAccount - UID_ADSContainer ='xxxx' and ADSAccount - UID_HomeServer ='xxxx' ..

    what is that actually implies.

  • Is there any any custom  task for re-assigning default AD groups to all users in One idm. Because many users missing one default group so instead of assigning individually,do i have any bulk task for assigning to all.