Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-10602: ZPA Error Log: "Failed to load foreignSecurityPrincipal of sid S-1-2-34-567890-1234567890-12345678-9012345 when enumerating group member: The server is not operational."

Authentication Service ,  

29 June,18 at 10:52 PM

Problem:
The Zone Provisioning Agent fails to complete, investigations into the debug logs reveal the following message:

[2018-01-01 12:34:56.789 -0123] Centrify.Provisioning.Agent.exe[1234,5] Verbose: DomainCache.GetEntryFromFsp: Failed to load foreignSecurityPrincipal of sid S-1-2-34-567890-1234567890-12345678-9012345 when enumerating group memeber: The server is not operational.

A user or group is included as a member of a provisioning group, but the ZPA service is unable to ascertain the location and further details of the object. This is often the case when the foreign domain is either currently offline, separated by a firewall, or on the other side of a one-way trust.


Resolution:
In order for the ZPA to complete its provisioning the connection must be corrected to find the user or group. The other option would be to remove the foreign user or group and allow provisioning of users and groups to complete until the connection may be investigated further.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.