This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Account Provisioning Error. Corporate policy violation

Hello Everyone, 

I have just run in to an error whilst trying to provision an AD Account using an Account definition. 

Just to give some background information, I am using the ARS connector to connect to their AD environment. I am able to pull in information with a sync and was even able to provision AD accounts perfectly up until recently.

It turned out that the customer didn't transfer the policies from their production environment in to Dev / UAT and all of a sudden, i am now not able to provision after the move. 

I have been working with the AD admin and have met all of the requirements for the policies however it doesn't seem to be making any difference. 

For example the error in the screenshot below shows that the Firstname / Givenname property does not conform to their policy. I don't understand how this is occurring as the policy just states that the field should be mandatory and before the policies were applied, it was creating AD accounts using this property.

I have seen the page for a similar issue in ARS and have referred it to the Admin. 

https://support.oneidentity.com/active-roles/kb/215373 

 

Also I am using v7.1

Any help or guidance would be greatly appreciated

 

Thanks 

Yahya

Parents
  • When working on issues such as this, what I usually do is block inheritance on the policies then attempt to create a test user. I would suggest blocking the policies that relate to users one by one then test. That will tell you which policy is breaking it. 

     

Reply
  • When working on issues such as this, what I usually do is block inheritance on the policies then attempt to create a test user. I would suggest blocking the policies that relate to users one by one then test. That will tell you which policy is breaking it. 

     

Children
No Data