A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer exists as user access causing errors in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-23
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
Issue
Scenario
User accounts belonging to AD groups are later given access to the same AD groups via a role.A termination rule to trigger for terminated users with action to disable and delete the accounts will trigger when the user is terminated.
If you try to remove the access to role, the change request also tries to remove the indirect AD entitlement and the AFX fulfillment fails with an error:
Cause
Resolution
This issue is fixed in 7.0.2 P14, 7.1.0 P07, and 7.1.1 P01.
Related Articles
A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer ex… 52Number of Views A completed change request to remove Aveksa Application/Directory entitlements from a user does not remove the access from… 196Number of Views Workaround to remove duplicate identities resulted to mapping of account to a terminated account instead of the active one 80Number of Views How to remove all user data stored in the RSA Identity Governance and Lifecycle application database 736Number of Views Access Fulfillment Express (AFX) AD LDAP connector fails to remove AD account with error "Not Allowed On Non-leaf" in RSA … 187Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?