
Answer-first summary for fast verification
Answer: Correct the permissions on the Active Directory group so that IAM Identity Center has read access.
For IAM Identity Center with AD, the connector needs read permissions on the AD groups and users to sync and assign permissions. If 'Domain Users' group doesn't have proper delegation for Identity Center to read members/attributes, it fails. Time sync or re-adding not relevant.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
A SysOps administrator uses IAM Identity Center with Active Directory. A new account was added and the Active Directory "Domain Users" group was assigned permissions. Users still get access denied. What resolves this?
A
Create a new group; add users to provide access.
B
Correct the time on the Active Directory domain controllers.
C
Remove and re-add the account to the organization.
D
Correct the permissions on the Active Directory group so that IAM Identity Center has read access.
No comments yet.