Support Center > Search Results > SecureKnowledge Details
Unable to obtain LDAP groups from ISE users Technical Level
Symptoms
  • pdp monitor command does not show access roles based on LDAP groups for users that are obtained from ISE server.
  • In Pdp debug (' pdp debug set all all '), the following log is seen:
    PDPOverridingAttrs::AttributeExists: Attribute idc_consolidate_groups exists: No
Cause
  • Attribute that enables LDAP group fetch for ISE users is disabled even tough the command 'pdp idc groups_consolidation status' shows enabled.

Solution
Note: To view this solution you need to Sign In .