Active Directory filter in Cortex XDR has no result when searching AD group after successfully setting up Cloud Identity Engine
1537
Created On 09/05/22 03:11 AM - Last Modified 09/04/25 02:42 AM
Symptom
After following the setup guide for Cloud Identity Engine and successfully adding it in Cortex XDR, the Cortex XDR Active Directory details are available but the Active Directory Filter has no result when searching the AD group.
Environment
- Cortex XDR
- Cloud Identity Engine
Cause
Another domain (dummy domain) which is not configured on the endpoint is synced with the Cloud Identity Engine instance. The dummy domain is not sync correctly and causing the issue.
Resolution
- Remove the dummy domain with sync failed error from Cloud Identity Engine instance.
- delete the dummy domain from Cloud Identity Agent’s LDAP Configuration
- remove the dummy domain from Cloud Identity Engine App>Directories
- Delete the existing Cloud Identity Engine configuration in Cortex XDR and add it again. In the Cortex XDR app, go to Settings>Configuration>Integrations>Cloud Identity Engine