After upgrading to One Identity Manager 9.2.2, LDAP synchronization may fail for newly created LDAP groups that do not yet have any members.
This is a known LDAP limitation. The groupOfNames object class (and similar LDAP group schemas) does not allow empty groups and requires at least one member attribute. Therefore, LDAP automatically assigns a placeholder user (for example, nobody) when a new group is created. Since this placeholder does not exist in One Identity Manager, synchronization cannot resolve it and reports an error.
Recommended:
Configure the member property mapping in the Synchronization Editor to exclude the placeholder account (for example, member DN ≠ uid=nobody,...). Verify the exact DN used in your LDAP environment before configuring the filter.
Alternative options:
* Use a dedicated disabled LDAP placeholder account that exists in One Identity Manager.
* If supported by the LDAP server, modify the LDAP schema to allow empty groups.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center