Issue
When attempting to view members of an Active Directory group from permissions analysis results, an error window displays which includes the following message:
System.Exception: Cannot get the members of the group [domain\group] possibly because of network or permissions problems
Possible Reason
The ControlPoint Service Account does not have permissions to read all users within the Active Directory group.
Resolution
Make sure the ControlPoint Service Account has at least Read Permissions for the Active Directory record of every SharePoint user. Consult your Microsoft Active Directory documentation for details.
Issue
After clicking [Calculate Totals] On the ControlPoint Properties dialog, the number of Total Users with Permissions is followed by (Incomplete).
Reason
An exception was encountered when Active Directory users were being counted. Possible reasons include:
·The ControlPoint Service Account does not have access to an entire Active Directory group or one or more accounts within an Active Directory group.
·Networking problems have been encountered.
Resolution
Review the ControlPoint Administration Log (xcAdmin.log) to determine the cause of the exception.
Issue
One or more users who have permissions to SharePoint objects through a claim are not being included in permissions analysis results.
Possible Reason
If your SharePoint farm includes claims-based authentication, permissions granted through a claim may not be reliably reported because SharePoint only retains permissions information for an augmentation claims-based user for a limited time after the user logs in.
The same behavior can be observed in SharePoint. For example, the SharePoint Site Permissions > Check Permissions feature may or may not show permissions granted through an augmentation claim, depending on when the user last logged in.
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. 使用条款 隐私 Cookie Preference Center