Troubleshooting
This topic provides information to help you resolve potential issues that you might encounter when using the integration of CrowdStrike Falcon Fusion SOAR with Secret Server.
| Issue | Possible Cause | Resolution |
|---|---|---|
| Authentication failure (401) | Incorrect username, password, or Grant Type | Verify that the credentials match the API user created in Creating an Application Account in Secret Server. Confirm that Grant Type is set to password. |
| Connection timeout | Incorrect Tenant URL or network issue | Verify the Tenant URL format. Ensure that the Secret Server Cloud instance is reachable. |
| "Update User" action fails | Unlimited Admin Mode is not enabled. | Enable Unlimited Admin Mode. For details, see (Optional) Enabling Action-Specific Settings. |
| "Sync AD" action fails | Directory Services is not enabled | Enable Directory Services. For details, see (Optional) Enabling Action-Specific Settings. |
| Insufficient permissions | The application account lacks the Administrator role. | Assign the Administrator role to the application account. For details, see Creating an Application Account in Secret Server. |
| Configuration saved in Falcon Content Library with errors | One or more required fields in the Delinea Secret Server SOAR Actions app configuration were entered incorrectly. |
|
| The "List Users" action does not return user data from Secret Server. |
|
|
| The "Lookup Secrets" action does not return secrets from Secret Server. | The secrets being queried are not within the application account's accessible folder scope, or the search parameters passed to the action (such as search term, folder ID, or template filter) do not match any secrets visible to that account. |
|
| “List Secret Folders" does not return folder structure. |
|
|
| The workflow execution log shows authentication failures. |
Authentication failures in the execution log indicate that the OAuth token request to Secret Server is being rejected. The most common causes are:
|
|