000037392 - A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer exists as user access causing errors in RSA Identity Governance & Lifecycle

Document created by RSA Customer Support Employee on Jun 5, 2019
Version 1Show Document
  • View in full screen mode

Article Content

Article Number000037392
Applies ToRSA Product Set: Identity Governance & Lifecycle
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
 
IssueA change request to remove role access from a user tries to remove an AD group entitlement (indirect access from a role) which no longer exists as user access. This causes errors in the change request and the change request cannot be completed.

Scenario


User accounts belonging to AD groups are later given access to the same AD groups via a role.
 
User-added image
 


User-added image
 


User-added image



A termination rule to trigger for terminated users with action to disable and delete the accounts will trigger when the user is terminated.

User-added image


User-added image

User-added image

User-added image

If you try to remove the access to role, the change request also tries to remove the indirect AD entitlement and the AFX fulfillment fails with an error:



User-added image

User-added image
CauseWhen a user is given group access via an account and later given the same group access via a role and the account is then deleted from the user, the group also gets deleted. When the role is explicitly removed from the user, the deleted group is listed as a change request item under the user changes and the change request attempts to remove the group access again.
 
Resolution
This issue is fixed in 7.0.2 P14, 7.1.0 P07, and 7.1.1 P01.
 

Attachments

    Outcomes