KB-10602: ZPA Error Log: "Failed to load foreignSecurityPrincipal of sid S-1-2-34-567890-1234567890-12345678-9012345 when enumerating group member: The server is not operational."
Problem: The Zone Provisioning Agent fails to complete, investigations into the debug logs reveal the following message:
[2018-01-01 12:34:56.789 -0123] Centrify.Provisioning.Agent.exe[1234,5] Verbose: DomainCache.GetEntryFromFsp: Failed to load foreignSecurityPrincipal of sid S-1-2-34-567890-1234567890-12345678-9012345 when enumerating group memeber: The server is not operational.
A user or group is included as a member of a provisioning group, but the ZPA service is unable to ascertain the location and further details of the object. This is often the case when the foreign domain is either currently offline, separated by a firewall, or on the other side of a one-way trust.
Resolution: In order for the ZPA to complete its provisioning the connection must be corrected to find the user or group. The other option would be to remove the foreign user or group and allow provisioning of users and groups to complete until the connection may be investigated further.