Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7457: Show effective user rights for computer shows empty

Centrify DirectControl ,  

14 September,16 at 09:22 PM

Applies to: Centrify DirectManage Suite 2016.1 (5.3.1) on all OS versions

Problem:
Show effective user rights for a computer within Access Manager shows empty / no users.

Cause:
This issue may occur when there are duplicate computer role/zone objects housed in Active Directory. 

Resolution: 
Determine if there are any duplicate msDS-AzScope objects. The CN will likely be unique, however duplicates may be tracked via the value contained within the msDS-AzScopeName attribute of the objects.

An easy method for checking for duplicate objects is to run an ldap search to print the msDS-AzScopeName for msDS-AzScope objects within the domain (must be run as root):

# /usr/share/centrifydc/bin/ldapsearch -QLLLrm "(objectClass=msDS-AzScope)" msDS-AzScopeName

Once duplicate objects have been discovered, open ADSIedit or ADUC with 'View>Advanced Features' enabled. Navigate to the duplicate msDS-AzScope location and delete the older msDS-AzScope object that is the duplicate.  

Test show effective user rights for problematic computer.

Please also review:
KB-7301: Upgrading Access Manager 5.2.2 and below to 5.3.1 show effective user rights blank

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.