Preview Tool

Cisco Bug: CSCun81726 - ACS5.5 not able to retrieve userAccountControl attribute from AD

Last Modified

Nov 27, 2020

Products (1)

  • Cisco Secure Access Control Server Solution Engine

Known Affected Releases


Description (partial)

ACS  is not able to retrieve user attribute "userAccountControl" from Active Directory.

Authorization will not match rule if the attribute is used as a condition.

Error in the ACS authentication details log:
24100  Some of the expected attributes are not found on the subject record.
24458 Not all Active Directory atttributes are retrieved successfully

The attribute is missing in the authentication details log - section Authentication -> Other -> Other Attributes

Upgrade from ACS 5.x to 5.5.
New installation of ACS 5.5.
AD attribute userAccountControl is used in the authorization policy.
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.