SAP Knowledge Base Article - Preview

1741451 - After migrating objects via incremental upgrade using Upgrade Management Tool, AD and/or LDAP groups no longer add users

Symptom

  • After migrating AD or LDAP groups via incremental or full upgrade using Upgrade Management Tool Adding new AD/LDAP groups doesn't add users
  • Following steps in KBA 1608901 or KBA 1635277 for migrating 3rd party groups in UMT results in a condition where adding new AD groups succeeds but users do not synch
  • If you run the query in query builder select * from ci_systemobjects where si_name = 'secWinAD' in the results will be the si_mapped_groups one of more values in that field will have the DN instead of sid which is the root cause of this issue
  • users can be added and deleted manually in the users and groups section but cannot be added or removed with the update button or scheduled objects in the authentication plugins
  • It is possible that this issue or symptoms could be caused by a number of as yet undetermined factors. The final fix in patch will hopefully address all issues that result in this problem with the si_mapped_groups
  • Receive error invalid group name, cannot find group followed by a SID or list of SID's when hitting update or enabling AD/LDAP plugin in CMC


Read more...

Environment

SAP BusinessObjects Business Intelligence Platform 4.0 SupportPack 04 (SP4)

Product

SAP BusinessObjects Business Intelligence platform 4.0

Keywords

zie BI4 SP4 support pack Objects ADAPT 01651905 01644195 1651905 1644195 user synch issue, not showing users, can't add AD plugin not working , KBA , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , BI-BIP-DEP , Webapp Deployment, Networking, Vulnerabilities, Webservices , Bug Filed

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.