and more in a single search tool across platforms. Read the announcement here. |
05/11/2022 02:16 PM
Hello,
I am noticing an issue when the Remove Account task runs to delete an Active Directory account that there is an error message that states the follow:
2022-04-28 15:40:38,154 [quartzScheduler_Worker-2] DEBUG ldap.SaviyntGroovyLdapService - enforceTreeDeletion:
2022-04-28 15:40:38,454 [quartzScheduler_Worker-2] DEBUG ldap.SaviyntGroovyLdapService - Cannot delete object as object contains child objects also:
javax.naming.ContextNotEmptyException: [LDAP: error code 66 - 00002015: UpdErr: DSID-031A12B0, problem 6003 (CANT_ON_NON_LEAF), data 0
Is there a way to specify deletesubtree/enforceTreeDeletion in the REMOVEACCOUNTACTION on the AD connector?
05/12/2022 02:04 AM
Hi Team,
If you are using the Active Directory Connector, we have the parameter 'ENFORCE_TREE_DELETION' on the AD Connector :
By default it is FALSE, please set it to TRUE and try provisioning again.
05/12/2022 08:38 AM
Thank you for the information. I set the ENFORCE_TREE_DELETION to TRUE and re-ran the task. The child object was deleted but still fails to delete the account with the error message:
DEBUG ldap.SaviyntGroovyLdapService - Cannot delete object as object contains child objects also:
javax.naming.ContextNotEmptyException: [LDAP: error code 66 - 00002015: UpdErr: DSID-031A12B0, problem 6003 (CANT_ON_NON_LEAF), data 0
Is there another way to force the deletion?
05/12/2022 08:54 PM
Hello,
Since the leaf objects are now deleted, does rerunning the provisioning still give the same provisioning response?
05/13/2022 06:16 AM
Yes, I have tried running the task two more times after the original child object was deleted and it still gives the same error message in the logs. Is there a way to tell AD to delete despite this message?
05/15/2022 11:07 PM
That is not expected. Are you looking at the error message from the Provisioning comments on the task or from the logs?
05/17/2022 12:46 PM
I am able to see the error message in the logs and then also verify in Active Directory that the account was not deleted. Is there any other configurations that need to be made to allow the deletion to go through?
05/18/2022 05:57 AM
Hello,
This seems odd as if the child object gets deleted, the intended object should also get deleted in the next provisioning run. Could you please raise a Freshdesk support ticket with Saviynt Support and work with the Ops team to get the issue triaged?