Security Compliance
Group membership is not updated in ARM after creating a new AD account
After creating a user and assigning group memberships, ARM does not immediately display the user in the group membership list. However, verifying directly in Active Directory confirms the user is a member of the assigned groups.
First published date
Last published date
Overview
When a new Active Directory user is created and added to groups, ARM may not immediately reflect these group memberships in the application.
While the user appears as a member of the groups in Active Directory, the memberships are not visible in ARM until the next scheduled scan. This issue occurs specifically when multiple groups are assigned at once; assigning a single group updates correctly without delay.
Product section
Cause
This has been identified as a known issue in ARM.
Resolution
A fix is planned for a future release of ARM. Watch this article for updates.
As a workaround, a manual AD scan can be run to update group memberships in ARM immediately.