Resolving delayed or missing DA.live access via IMS groups
This article explains how to resolve delayed or missing access to DA.live when access is managed through IMS groups in the Adobe Admin Console. Changes to IMS group membership do not appear immediately in DA.live because synchronization and caching processes require time to complete. To resolve the issue, verify group assignments, access control configuration, and sign-in status to ensure access is granted correctly.
Description description
Environment
- DA.live (all versions)
- Adobe Admin Console
- IMS Groups
Issue/Symptoms
- Users added to IMS groups in the Adobe Admin Console do not receive DA.live access immediately.
- No error message appears when users are added to an IMS group.
- Access is delayed by several hours and may take up to 24 hours.
- Users added directly to the DA.live access control list receive access immediately.
- Some users receive an unauthorised message when accessing DA.live after being added through an IMS group.
Root cause
IMS group membership changes do not propagate to DA.live in real time. Synchronization and caching intervals exist on both the IMS and DA.live sides, and no immediate push mechanism is available. Users may also continue to use outdated group memberships if they do not fully sign out and sign back in.
Resolution resolution
Follow the steps below to resolve the issue:
- Add users to the appropriate IMS group in Adobe Admin Console.
- Ensure that the organization and group identifiers in Adobe Admin Console exactly match the identifiers configured in the DA.live access control list for the relevant site or path.
- Instruct users to sign out of DA.live completely and sign back in after being added to the IMS group. If prompted, ensure that the correct organization is selected during sign-in.
- Allow up to 24 hours for group-based access changes to propagate, especially after large updates or when using newly created groups.
- If immediate access is required, add the user’s email address directly to the DA.live access control list for the relevant path. Remove the direct access entry after group-based access is confirmed.
- If access is still unavailable after 24 hours, verify that the user is a member of the correct IMS group in Adobe Admin Console, confirm that the DA.live access control list contains the correct organization and group identifiers, verify that the required permissions are granted to the same organization and group, and ask the user to sign out and sign back in again.
- If access issues continue beyond 24 hours, contact Adobe Support and provide the affected user’s email address, the organization and group identifiers, the time the user was added to the group, the time access was granted if applicable, and confirmation that the user signed out and signed back in.