Skip to content

Troubleshoot Physical Access Control administration

The Physical Access Control card is missing

Confirm the selected site has the Physical Access Control module and that your account is assigned to the site with Site Admin-level authority, Access Control Admin, or Access Control Viewer. A viewer can open the area but cannot modify it.

Reader or Reader Group is missing

Those legacy actions are hidden when all active site systems are Azure or AllBox. Use the Azure controller's Hardware Setup for modern hardware. Also confirm that at least one non-deleted controller of another type exists.

Card Formats is missing

Card Formats requires Global Client Admin authority or higher. Ask an authorized administrator to create or review the format; do not substitute an arbitrary Format ID.

An external-ID selector is empty

Schedules, Azure/VertX readers, reader groups, and Azure/VertX access groups select unused IDs from 1 through 500. Remove an obsolete record only after migrating its dependencies, or correct duplicate/out-of-range legacy data through an approved support process.

A saved change is not working at the door

A portal save does not prove controller delivery. Confirm the correct controller, synchronize the relevant record type, inspect Configuration Status, check controller health, and test the complete chain: card format → credential → access group → reader/access point → schedule.

A controller sync button is missing

Schedule, reader, reader-group, and access-group sync actions are VertX-specific in these dialogs. The action is hidden when there is no active eligible VertX controller, the record has no syncable mappings, or the user is read-only.

An access group will not save

Confirm Name, System Type, External ID, and at least one association appropriate to the type. VertX needs a reader group and schedule; Azure and AllBox need reader/schedule associations; Azure can also use access point/strike/schedule; DSX accepts its supported legacy or modern association.

If you canceled a controller-credential-removal prompt, reopen the group. Core metadata can be saved before that prompt even though association replacement was canceled.

A schedule window is skipped

The candidate overlaps an existing unremoved entry for the same day. Endpoints are inclusive, so a window beginning exactly when another ends also conflicts. Remove or shorten the old entry, save, and then add the replacement.

Deleting a schedule changed other configuration

Schedule deletion intentionally clears reader hold-open, input mask, output control, and queued-command references and removes access-group associations. Recreate the schedule, restore each association, synchronize affected controllers, and test.

A credential number is reported as already in use

Search by Credential Number and include deleted credentials. Identity is based on site, card-format external ID, and credential number. Creating a matching record can restore a deleted credential, but it cannot overwrite an active one.

A credential is active but access is denied

Check Valid From, Expiration, Max Use Count, card format, facility code, and every assigned access group's schedule and controller coverage. Then confirm that the credential and its dependency configuration reached the controller.

A bulk operation completed only partially

Bulk actions and range creation process records individually in background threads. Refresh, narrow the grid to the original selection, compare counts, review history and queue results, and retry only failed records. Do not repeat the full set without reconciliation.

Imported rows are missing

Review the emailed import log. Common causes include a comma inside a field, a non-exact access-group name, unknown host/vendor import ID, invalid required date, unknown credential type, missing required column, or an existing active credential. An invalid optional expiration date can be silently treated as no expiration, so inspect imported records even when the row is not listed as failed.

A disabled queue command still reached the controller

The command may already have been consumed before it was disabled. Disabling prevents future eligibility; it cannot recall in-flight work. Determine the controller's actual state and send an approved corrective configuration.

Support information to collect

Include site, controller name and type, controller online/last-seen state, record IDs and external IDs, credential number and format, access groups and schedules, queue command/result/request time, audit or credential history, and the exact physical test performed.