Security Compliance

Group membership is not updated in ARM after creating a new AD account

After creating a user and assigning group memberships, ARM does not immediately display the user in the group membership list. However, verifying directly in Active Directory confirms the user is a member of the assigned groups.

First published date

3/7/2025 11:23 AM

Last published date

12/8/2025 4:06 PM

Overview

When a new Active Directory user is created and added to groups, ARM may not immediately reflect these group memberships in the application.

While the user appears as a member of the groups in Active Directory, the memberships are not visible in ARM until the next scheduled scan. This issue occurs specifically when multiple groups are assigned at once; assigning a single group updates correctly without delay. 

Product section

Access Rights Manager

Cause

This has been identified as a known issue in ARM.

Resolution

A fix is planned for a future release of ARM. Watch this article for updates.

As a workaround, a manual AD scan can be run to update group memberships in ARM immediately.