This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Account Provisioning Error. Corporate policy violation

Hello Everyone, 

I have just run in to an error whilst trying to provision an AD Account using an Account definition. 

Just to give some background information, I am using the ARS connector to connect to their AD environment. I am able to pull in information with a sync and was even able to provision AD accounts perfectly up until recently.

It turned out that the customer didn't transfer the policies from their production environment in to Dev / UAT and all of a sudden, i am now not able to provision after the move. 

I have been working with the AD admin and have met all of the requirements for the policies however it doesn't seem to be making any difference. 

For example the error in the screenshot below shows that the Firstname / Givenname property does not conform to their policy. I don't understand how this is occurring as the policy just states that the field should be mandatory and before the policies were applied, it was creating AD accounts using this property.

I have seen the page for a similar issue in ARS and have referred it to the Admin. 

https://support.oneidentity.com/active-roles/kb/215373 

 

Also I am using v7.1

Any help or guidance would be greatly appreciated

 

Thanks 

Yahya

Parents
  • If you still have the frozen job present in the job queue you could enable the process step option under the view menu and then expand the basisobjectkey for this object and confirm what the given name value is that is trying to be passed to Active Roles. Just scroll down until you see given name

     

     

    You can do the same if the job is now in process history

     

Reply
  • If you still have the frozen job present in the job queue you could enable the process step option under the view menu and then expand the basisobjectkey for this object and confirm what the given name value is that is trying to be passed to Active Roles. Just scroll down until you see given name

     

     

    You can do the same if the job is now in process history

     

Children
No Data