When working with Support or when investigating issues, it may be necessary to gather logging from certain components in order to diagnose a root cause. ... Please review the below solutions for instructions on gathering these logs.
Active Roles Licensing ... The following article explains Active Roles Licensing:
Active Roles 7.0 supports Windows 10 for the Active Roles Console (MMC).
You can start, stop or restart the Administration Service by clicking the Start, Stop or Restart button at the top of the Administration Service page in the Configuration Center main window.
From the Administration Service page in the Configuration Center main window, click Change in the Service account area. ... In the wizard that appears, supply the logon name and password of the domain user account in which you want the Administration Service to run.
In the wizard that appears, specify the SQL Server instance and the database you want the Administration Service to use, and choose the database connection authentication mode (Windows authentication or SQL Server login).
Please refer to feature guide for details.
On the Administration Service page in the Configuration Center main window, you can view the state of the Administration Service. ... Please refer to the Feature Guide for further details.
Please refer to feature guide for details.
In the wizard that appears, specify the group that you want to have the Active Roles Admin rights.
Which version of TLS (Transport Layer Security) is supported by the Active Roles Web Interface? <p>Active Roles 7.2.x and later versions support TLS 1.2</p> ... <p><strong>Note:</strong> Disabling TLS in an environment has no impact on Active Roles. There may be other dependencies in your environment that may require updating when upgrading the version, or when disabling this protocol.</p>
After upgrading to Active Roles 8.2.x, delegated Active Roles Users are now encountering error when attempting to move objects into or out of containers where in previous versions, the delegated permissions were sufficient.
Operations made on native Active Directory by native Active Directory clients such as Active Directory Users and Computers or Active Directory PowerShell will not be recorded in Active Roles Change History.
How will Active Roles handle the ms-Mcs-AdmPwd attribute which is present after implementing LAPS? ... In Windows, the LAPS attributes are marked as confidential attributes in the Active Directory schema.
This article clarifies what communication port and URLs’ access is required by AR. ... <p>Port 443 needs to be opened on the firewall as well as the following ports:</p> ... <p> </p> ... <p><a href="https://support.oneidentity.com/kb/30256/communication-ports-for-active-roles" target="_blank">https://support.oneidentity.com/kb/30256/communication-ports-for-active-roles</a></p>
When running a query on Active Roles Management Shell to retrieve a group type, for example: ... The results for groupType return "Default" for a security group type. ... Active Roles Management Shell should return security as a result.
This article explains how to enable the Active Roles Administration service log and where the log is located. ... It should only be enabled during troubleshooting scenarios as the logs may grow quite large in a very short period of time.</p>
When running an inplace upgrade with 2 or more Active Roles instances, first Active Roles instance upgrades and creates Configuration and Management History DBs succesfully. ... When upgrading the next Active Roles server the following error appears:<br><br><strong>"Verification failed:<br><br>- The destination Configuration database already exists on the server.
The Active Roles Change History and Activity Reports shows entries in UTC format and not showing local time.
STATUS ... Enhancement Request 433324 has been logged to support LAPS version 2, and will be considered in a future release of Active Roles.
Change History is logging the activity changed in the Dynamic Group for all the users even if the users are not members of the group changed. ... The following <strong>Defect ID#: 421340</strong>, has been submitted to remove this behavior of logging Change History for Dynamic Groups of which the user is not a member.
Active Roles wipes down attributes in Azure such as MailEnabled and ProxyAddresses after the group becomes a hybrid by BackSync. ... If there is a mismatch in attribute values between AD On-Premises and Azure, as soon as the group becomes hybrid Active Roles will preserve and replicate the attributes from Active Directory.
There is a requirement to implement multiple Active Roles Admin service hosts in a standalone configuration. ... The first ARS Admin host STS has been successfully configured and works as expected, however the other ARS Admin service hosts ARS WI do not appear correctly configured, when trying to configure ARS WI to STS in a second ARS instance, in the page with the RSTS Proxy and port-number, the following error appears:
There may be a requirement to reduce the overall licensed user account total in an Active Roles environment. ... This will prevent using licenses when these objects are not in use and will prevent exceeding the total Managed Objects total.
Log in to the Azure portal at portal.azure.com ... Navigate to Azure Active Directory | App Registrations | Click on your App under Display name (Example: ActiveRoles_AutocreatedAzureBackSyncApp_V2) | Certificates & secrets.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center