Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Peter_Bjeldbak
Contributor
Jump to solution

Missing sync of AD security group from endpoint server

Greetings all !

 

I use a security group in my AD to pinpoint workstations eligible for FDE.  Thus I have rule,  where an AD security group is the dynamic "target"  - This has worked out perfectly so far.

Alas (otherwise i wouldnt be writing this post) the "link" seems broken to the AD security group.

I can see worksstations in my AD - but when looking into the deployment rules - the reflection of the group are missing several members .

As i understand - using security group for deployment secures dynamic updates - where virtual groups lack that ability.


 I have other rules depending on the AD connection - whích works fine - but those are based on virtual groups instead of Security groups.

I have tried removing said group and reapply it - to no avail.

I feel confident the connection between server and AD is at least partial working - since i can browse my AD from endpoint server.

Hope this makes sense !

Any ideas?

Kind regards

 

Peter

0 Kudos
1 Solution

Accepted Solutions
Peter_Bjeldbak
Contributor

SOLVED !!

So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)

After contacting suppport - I ended up with the below suggestion.

1. Enter SSH to the Endpoint Management Server.
2. cpstop
3. cd $UEPMDIR/engine/uepm-jms-data
4. rm *
5. cpstart

Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!

kind regards

Peter

View solution in original post

0 Kudos
3 Replies
G_W_Albrecht
Legend Legend
Legend

I would suggest to contact TAC to resolve this issue !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Michi
Participant

Do you have an AD Scanner running?
Secondly, the AD Scanner only checks in a frequency of 120 Minutes (TAC told me there is no shorter time span possible) for any changes in AD and syncs that into the CP DB.

This means that if you change a AD security group and add a Client - it can be up to 120min Delay in worst cases until CP notices that .. 

 

BR ME

^ME
0 Kudos
Peter_Bjeldbak
Contributor

SOLVED !!

So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)

After contacting suppport - I ended up with the below suggestion.

1. Enter SSH to the Endpoint Management Server.
2. cpstop
3. cd $UEPMDIR/engine/uepm-jms-data
4. rm *
5. cpstart

Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!

kind regards

Peter

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events