RM Logo
Technical Rating: 
Support Home PageSupport
Print This PagePrint This Page
Add to 'My Library' Add to 'My Library'

PRIMARYTSAFAILEDPROCESSING. User.... Current connection to Active Directory has corrupted in RM Unify User Audit Log
Published Date : 03 Feb 2023   Content Ref: TEC9008795  





Symptoms

You are using RM Unify Network Provisioning on a vanilla Windows network. A new RM Unify user account has been created, but the Network Agent fails to create or update the expected AD user account. The RM Unify User Audit log also reports the error message as below:

PRIMARYTSAFAILEDPROCESSING. User: <username>. Current connection to Active Directory has corrupted.



Cause

This can occur when an AD account has a User logon name value that matches the RM Unify username, but the sAMAccountName attribute has a different value. 

The Network Agent tries to match the RM Unify username to an AD account with a matching sAMAccountName value. If it fails to find one, it tries to create a new AD account, but is unable to because the RM Unify username value is already in use as a User logon name of another AD user account.



Requirements

For successful user creation, the RM Unify username should not already be in use as the User logon name or sAMAccountName of another AD account.

For successful user matching, both the User logon name and sAMAccountName attributes of the existing AD user account should match the RM Unify username.



Procedure

To create a new AD account
  1. In the RM Unify Management Console, rename the user to a value that is not in use on the network.
  2. Wait five minutes and check for a successful message in the RM Unify User Audit log:
    Create AD User     SUCCESS User: <username>

To match to an existing AD account
  1. In Active Directory Users and Computers, select to view the Properties of the user account.
  2. Click the Attribute Editor tab.
  3. Confirm the following attributes are <notset>:
    rmCom-ImmutableIdentityGuid
    rmCom-ManagementInfo
    rmCom-Misid
    rmCom-OrganisationGuid
    Note: If the attributes are populated with values, do not proceed with the remaining steps and contact your usual RM Unify support team for further assistance as the AD account may already be linked to another RM Unify user.
  4. Click the Account tab.
  5. Update the sAMAccountName attribute of the existing AD account to match the RM Unify username. 
    Note: Before doing so, please ensure you have communicated the intended change to the end user so they are aware of any changes this may make to the way they log on, or access resources on the network or to connected apps.
  6. Click OK.
  7. In the RM Unify Management Console, disable and then enable the RM Unify user account.
  8. Wait five minutes and check for a successful message in the RM Unify User Audit log:
    Update AD User    SUCCESS. User <username>.  Found match with an existing user and set management attributes..."


FEEDBACK
Did the information in this article help answer your question?
 Yes
 No
Please add any comments about this article in the box below. If you answered No then it is important you tell us why so that we can change the article if required. We can only respond if you log in to the RM Support website or provide your contact details. Note: If you need help with a technical query, please log a call online or telephone our support team.
Thank you for your feedback, which is sent directly to the RM Knowledge team. We address every message received with the intention of improving our Knowledge Library articles. If you have an unresolved technical issue, please contact RM Support.


If this article has not helped provide a solution then it is also possible to log a call...



Document Keywords: mgt console, auditing, user audit, event type, rm unify audit, audit log, rmunp, rmunvp, fail to update,


Please read - important disclaimer information.
http://www.rm.com/_RMVirtual/Includes/csredirect.asp?cref=&title=Standard Content Disclaimer


Top Of PageTop of page