- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: Missing sync of AD security group from endpoin...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Missing sync of AD security group from endpoint server
Greetings all !
I use a security group in my AD to pinpoint workstations eligible for FDE. Thus I have rule, where an AD security group is the dynamic "target" - This has worked out perfectly so far.
Alas (otherwise i wouldnt be writing this post) the "link" seems broken to the AD security group.
I can see worksstations in my AD - but when looking into the deployment rules - the reflection of the group are missing several members .
As i understand - using security group for deployment secures dynamic updates - where virtual groups lack that ability.
I have other rules depending on the AD connection - whích works fine - but those are based on virtual groups instead of Security groups.
I have tried removing said group and reapply it - to no avail.
I feel confident the connection between server and AD is at least partial working - since i can browse my AD from endpoint server.
Hope this makes sense !
Any ideas?
Kind regards
Peter
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SOLVED !!
So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)
After contacting suppport - I ended up with the below suggestion.
1. Enter SSH to the Endpoint Management Server.
2. cpstop
3. cd $UEPMDIR/engine/uepm-jms-data
4. rm *
5. cpstart
Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!
kind regards
Peter
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suggest to contact TAC to resolve this issue !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have an AD Scanner running?
Secondly, the AD Scanner only checks in a frequency of 120 Minutes (TAC told me there is no shorter time span possible) for any changes in AD and syncs that into the CP DB.
This means that if you change a AD security group and add a Client - it can be up to 120min Delay in worst cases until CP notices that ..
BR ME
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SOLVED !!
So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)
After contacting suppport - I ended up with the below suggestion.
1. Enter SSH to the Endpoint Management Server.
2. cpstop
3. cd $UEPMDIR/engine/uepm-jms-data
4. rm *
5. cpstart
Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!
kind regards
Peter
