RM Logo
Technical Rating: 
Support Home PageSupport
Print This PagePrint This Page
Add to 'My Library' Add to 'My Library'

What to do when RM Unify AD Sync is spamming data
Published Date : 07 May 2015   Last Updated : 25 Jul 2024   Content Ref: TEC4526625  





Symptoms

RM Support has been in contact to advise the RM Unify AD Sync software installed on your network is spamming (sending excessive and\or unwanted data to) the RM Unify datacentre. This document details the steps to stop spamming.


Cause

There are three known causes of spamming:

  1. The RM Unify AD Sync server date/time is not correct and is skewed by more than + or - five minutes.
  2. There are insufficient security permissions on the RMNetIdentityQueue folder on one or more domain controllers.
  3. The RM Unify AD Sync Service is not configured to log on as the identitysyncservice user. 


Requirements

Please follow each of the check sections below and then reregister RM Unify AD Sync. If you are an RM Managed Service site using RM User Provisioning you should also reregister the RM CSV Retrieval Tool.


Procedure

Check the RM Unify AD Sync server date/time
  1. Identify your RM Unify AD Sync server. This server will be running a service called RM AD Sync Service.
  2. Ensure the date/time on your RM Unify AD Sync server is synchronised correctly. Please see your normal network provider for assistance with this or contact RM Support for assistance.
  3. If you have changed the time, please restart the RM Unify AD Sync Service.

Check permissions on the RMNetIdentityQueue folders

On your RM Unify AD Sync server and on each of your domain controllers (that have the RM Unify Password Filter installed):

  1. Browse to the C:\Program Files\RM\RM Unify Password Filter folder.
  2. Right-click the RMNetIdentityQueue folder and select Properties.
  3. Click Sharing, Advanced Sharing, Permissions.
  4. Confirm the Everyone group has been granted full control. If not, click Add to select the Everyone group and assign Full Control permissions.
  5. Click OK to close the Sharing tab window.
  6. Click the Security tab.
  7. Click the identitysyncservice user and click Advanced.
  8. Confirm the identitysyncservice user has been granted Modify permission and that it applies to 'This folder, subfolders and files'.
  9. If it does not, update the permissions accordingly.
  10. Click OK to close all windows.
  11. In Windows® Explorer, browse to C:\Program Files\RM\RM Unify Password Filter folder\RMNetIdentityQueue.
  12. Check if this folder contains one or more .bin or .json files.

When permissions are correct, RM Unify Password Filter will create a .bin or .json file every time the domain controller detects a password change. The file is then deleted automatically when it has been processed in 1-5 minutes. If the folder contains .bin or .json files older than this then the individual files may also have inherited insufficient security permissions. To resolve, update the permissions on all the .bin and .json files to ensure the identitysyncservice user has Modify permissions.


Check the RM Unify AD Sync Service
  1. On your RM Unify AD Sync server, click Start, Run and type services.msc and press Enter. 
  2. Confirm the RM Unify AD Sync Service is set to log on as identitysyncservice user. 
  3. If it is not, reset the identitysyncservice user's password in Active Directory and then update the RM Unify AD Sync Service to log on as the identitysyncservice user. 
  4. Stop and start the service.

Registration of RM Unify AD Sync

Once you have completed all of the above checks, reregister the RM Unify AD Sync to allow uploads to restart.

To reregister:

  1. Log on to RM Unify as a super admin user.
  2. Select Management Console (link at the top).
  3. Select 'Sync users from AD' (from the Sync section).
  4. In the 'AD Sync Service Registration Code' section, click 'Change registration code'.
  5. Note the new AD Sync Service Registration Code.
  6. On the RM Unify AD Sync server, open the RM Unify AD Sync Configuration Tool.
  7. Expand RM Unify Registrations.
  8. Select your site, the 'Organisation code' and 'Registration code' fields should show on the right-hand side.
  9. Enter the new registration code into the field.
  10. Click Save, followed by the Register button. After a short pause, a Successful Registration window should be displayed. Click OK and then close the RM Unify AD Sync Configuration Tool.

Note: If you have a Managed Service from RM and are using RM User Provisioning, then you will additionally need to reregister the MIS CSV Retrieval Tool.

  1. Navigate to C:\Program Files (x86)\RM\RM MIS CSV Retrieval Tool.
  2. Double-click RM.Networks.ConfigurationManager.exe to run the configuration editor.
  3. In the AD Sync Password field, enter the registration code.
  4. Click Update and then Test Settings to confirm the change was successful.


FEEDBACK
Did the information in this article help answer your question?
 Yes
 No
Please add any comments about this article in the box below. If you answered No then it is important you tell us why so that we can change the article if required. We can only respond if you log in to the RM Support website or provide your contact details. Note: If you need help with a technical query, please log a call online or telephone our support team.
Thank you for your feedback, which is sent directly to the RM Knowledge team. We address every message received with the intention of improving our Knowledge Library articles. If you have an unresolved technical issue, please contact RM Support.


If this article has not helped provide a solution then it is also possible to log a call...



Document Keywords: rm unify, ad sync, set up, set-up, Tool, spam, flood, TEC4526625


Please read - important disclaimer information.
http://www.rm.com/_RMVirtual/Includes/csredirect.asp?cref=&title=Standard Content Disclaimer


Top Of PageTop of page