• How to provision a new AD account to a user using Roles

    We are new to One Identity and trying to provision a new AD account by assigning a business role. Below is our approach:

    1. Created a business role hierarchy as below:

               Business Role1 ----- Role Assignment (Account Definitions, Active Directory Groups…

  • Need to understand the traffic generation from AD connector and Native Database connector

    Hello,

    We are using version 8.1.3 and we are using AD connector and Native Database connector which has connectivity with One IM database via Application Server. This is our QA environment and there is no major activity going on between One IM database…

  • How can we have Active Directory account same privileges as Viadmin user

    Hi,

    We are using version 8.0 and we have a requirement where in we don't want to use system user credentials to log in to the tools and instead we want to use Active Directory account credentials. In order to achieve this, we need to have viadmin privileges…

  • Unable to disable AD accounts from One Identity Manager

    Hi,

    I am trying to get the status of the user from CSV file and setting "IsTemporaryDeactivated" as True. But when IsTemporaryDeactivated is set to True from csv, it is not able to update AD account. And when I directly change IsTemporaryDeactivated to…

  • Unable to create/update AD account due to password policy

    Hi,

    We are trying to create an account in AD. It creates the account in AD but while setting the password it throws below error


    Error executing user_password_Set on object CN=91005,OU=Offsite Contractors,OU=US Berwyn,OU=all users,DC=dfctest,DC=local …

  • how to connect to admin tools using Active Directory password authentication?

    Hi,

    We are trying to connect to admin tools using "Active Directory Password" authentication and system type used is "SQL Server". Provided below values

    1. UserID : <Active Directory Domain>\<Username>

    2. Password : Password…

  • Getting error in AD synchronization

    Hi,

    I am trying to run AD sync and in the configuration, I have One IM connection via App server (configured in synchronization editor in AD project). When I run the sync, application server throws below error

    2019-01-30 15:10:09.3725 ERROR (ObjectLog…

  • unable to login to Password Reset Portal using "Active Directory" authentication module

    Hi,

    I am trying to login to Password Reset web portal using "Active Directioy" (tried all combination of AD authentication modules) authentication module but in some cases it is throwing error user cannot be determined and for Active Directory (manual…

  • Update query via Object Browser not getting provisioned to ADobjquer

    I have update some user attribute in ADSAccount via Object Browser query.But it is not triggering the provisioning workflow.But if i edit the user via Manger tool,it is triggering the provision workflow to update the attribute in AD.

    Could you please…

  • Unable to create AD project via Synchronization Editor

    Hi Experts,

    I am trying to create AD project via sync editor. But when I provide the AD details and try to save the project ("commit to database"), it gets hanged. Please help.

  • What is the difference between One Idm Active directory version vs Normal version vs Governance version.

    What is the difference between One Idm Active directory version vs Normal version vs Governance version. In all version having all the features.What the feature wise lacking of different versions and its advantage.

  • Changing the default shelf where Ad groups are auto-published

    Hello experts,

     

    We would like to publish our AD Groups in another shelf different from the default one. Version 7.1.2.

     

    We have tried to edit the script “ADS_AssignADSGroupsToITShop” which, as far as we know, contains the instruction to publish it in…

  • Got no DNS resolution querying gc._msdcs.RooTDOMAIN.COM.

    Hey All,

    We have run in to this issue and can't seem to find any support.  We are able to create groups, create users from OneIM to AD but when we try to provision group memberships for users, it returns an error 

    2018-07-23 00:37:54.6515 INFO (ObjectLog…

  • Events not getting triggered for assigning account definition to a user

    Hi,

    I want to assign account definition (account definition is created to provision account in AD) to a user but when I assign account definition directly to a user, only one DBQueue process is coming up in Job queue info and not the processes which follows…

  • Events not getting triggered for assigning account definition to a user

    Hi,

    I want to assign account definition (account definition is created to provision account in AD) to a user but when I assign account definition directly to a user, only one DBQueue process is coming up in Job queue info and not the processes which follows…

  • Getting error "Object reference not set to an instance of an object" in AD synchroniization

    Hi,

    I am getting error when I run synchronization of AD. Below is the error detail. Please suggest how can this be resolved


    (2018-06-04 10:43:50.097) Error saving iamcoelab: [810103] Error generating processes for event PostSync.
    [810222] Error executing…

  • Getting error "Error loading Authentication module ComponentAuthenticator" in AD provisioning as well as synchronization

    Hi,

    I am getting mentioned error when I run synchronization and provisioning for AD. It used to work till now and all of a sudden I got this error. What might have caused this issue to occur? Please suggest how this can be resolved.

  • Getting error "Write permission denied for value TSRemoteInteractWithSession" while running Active directory synchronization

    Hi,

    I am getting the mentioned error while running synchronization for importing data from Active Directory to One IM. In my environment, active directory is in different domain that One IM. Please suggest.

  • Unable to update user data in active directory.

    I am trying to update user data in AD. It runs the process ADS_ADSAccount_Update/(De-)activate but this process is throwing some error. Below is the screenshot of the error which I am getting when I manually update the data in ADSAccount table. I am unable…

  • How to assign active directory group account manager through ITshop ?

    My use case is: If the current account manager of AD group gets disabled, it gets removed as an account manager from the AD group which is as expected but now I want to assign new account manager to this AD group through ITshop and the workflow to assign…

  • Initial domain sync fails for DC in untrusted domain

    Hola,

     

    Ok so I have AD sync working fine from our integrated domain, but when adding a domain where there is no trust, I am having issues getting the sync to work.

    Couple of notes:

    • I am able to configure the connection in the Sync editor and browse the…
  • Problem with Publishing groups to AD

    We are running Identity Managmement 7.02, and have been running this for 7 months. We have an issue that happens intermittedly when new empoyees are created, they dont get their auto assigned groups in Active directory. This happens randomly to varyinging…

  • Error while Removing out of the box Active directory group from Manager

    I want to remove out of the box Service Category "Active Directory Groups" from the Identity Manager web portal.While removing this item from Service Catalog in Manager, I am getting below error.

    [1025012] Object (Active Directory Groups) could…

  • PWDLastSet

    Hi All.

    At present we use Password Manager along with Identity Manager. Should a user change their password throughout the day the user will eventually get their password reset prompt during the day after logging on successfully in the morning. If a user…

  • VI.JobService.JobComponents.ADSComponent - Errors occured

    Hello,

    I've recently upgraded to 6.13 in prep for 7.1. Since upgrading I get the following error randomly.

    2016-12-13 15:25:45 -06:00 - VI.JobService.JobComponents.ADSComponent - 389c90e6-1dae-4c33-8a98-ce2d4405833c: Errors occured
    The connection…