Published Date : 07 May 2015
Last Updated : 03 Oct 2024
Content Ref: TEC4526625
Operating System
(none)
Part No
(none)
Summary
Explains the procedure for repairing an RM Unify AD Sync installation which is spamming the RM Unify datacentre.
Symptoms
RM Support has been in contact to advise the RM Unify AD Sync software installed on your network is spamming (sending excessive and\or unwanted data to) the RM Unify datacentre. This document details the steps to stop spamming.
Cause
There are three known causes of spamming:
The RM Unify AD Sync server date/time is not correct and is skewed by more than + or - five minutes.
There are insufficient security permissions on the RMNetIdentityQueue folder on one or more domain controllers.
The RM Unify AD Sync Service is not configured to log on as the identitysyncservice user.
Requirements
Please follow each of the check sections below and then reregister RM Unify AD Sync. If you are an RM Managed Service site using RM User Provisioning you should also reregister the RM CSV Retrieval Tool.
Procedure
Check the RM Unify AD Sync server date/time
Identify your RM Unify AD Sync server. This server will be running a service called RM AD Sync Service.
Ensure the date/time on your RM Unify AD Sync server is synchronised correctly. Please see your normal network provider for assistance with this or contact RM Support for assistance.
If you have changed the time, please restart the RM Unify AD Sync Service.
Check permissions on the RMNetIdentityQueue folders
On your RM Unify AD Sync server and on each of your domain controllers (that have the RM Unify Password Filter installed):
Browse to the C:\Program Files\RM\RM Unify Password Filter folder.
Right-click the RMNetIdentityQueue folder and select Properties.
Click Sharing, Advanced Sharing, Permissions.
Confirm the Everyone group has been granted full control. If not, click Add to select the Everyone group and assign Full Control permissions.
Click OK to close the Sharing tab window.
Click the Security tab.
Click the identitysyncservice user and click Advanced.
Confirm the identitysyncservice user has been granted Modify permission and that it applies to 'This folder, subfolders and files'.
If it does not, update the permissions accordingly.
Click OK to close all windows.
In Windows® Explorer, browse to C:\Program Files\RM\RM Unify Password Filter folder\RMNetIdentityQueue.
Check if this folder contains one or more .bin or .json files.
When permissions are correct, RM Unify Password Filter will create a .bin or .json file every time the domain controller detects a password change. The file is then deleted automatically when it has been processed in 1-5 minutes. If the folder contains .bin or .json files older than this then the individual files may also have inherited insufficient security permissions. To resolve, update the permissions on all the .bin and .json files to ensure the identitysyncservice user has Modify permissions.
Check the RM Unify AD Sync Service
On your RM Unify AD Sync server, click Start, Run and type services.msc and press Enter.
Confirm the RM Unify AD Sync Service is set to log on as identitysyncservice user.
If it is not, reset the identitysyncservice user's password in Active Directory and then update the RM Unify AD Sync Service to log on as the identitysyncservice user.
Stop and start the service.
Registration of RM Unify AD Sync
Once you have completed all of the above checks, reregister the RM Unify AD Sync to allow uploads to restart.
To reregister:
Log on to RM Unify as a super admin user.
Select Management Console (link at the top).
Select 'Sync users from AD' (from the Sync section).
In the 'AD Sync Service Registration Code' section, click 'Change registration code'.
Note the new AD Sync Service Registration Code.
On the RM Unify AD Sync server, open the RM Unify AD Sync Configuration Tool.
Expand RM Unify Registrations.
Select your site, the 'Organisation code' and 'Registration code' fields should show on the right-hand side.
Enter the new registration code into the field.
Click Save, followed by the Register button. After a short pause, a Successful Registration window should be displayed. Click OK and then close the RM Unify AD Sync Configuration Tool.
Note: If you have a Managed Service from RM and are using RM User Provisioning, then you will additionally need to reregister the MIS CSV Retrieval Tool.
Navigate to C:\Program Files (x86)\RM\RM MIS CSV Retrieval Tool.
Double-click RM.Networks.ConfigurationManager.exe to run the configuration editor.
In the AD Sync Password field, enter the registration code.
Click Update and then Test Settings to confirm the change was successful.
If this article has not helped provide a solution then it is also possible to
log a call...
Document Keywords: rm unify, ad sync, set up, set-up, Tool, spam, flood, TEC4526625