A completed change request to remove Aveksa Application/Directory entitlements from a user does not remove the access from the user in RSA Identity Governance & Lifecycle
Originally Published: 2020-01-21
Last Modified: 2022-06-20
Article Number
Applies To
RSA Version/Condition: 7.0.x, 7.1.x, 7.2.x
Issue
In the following example, a request to remove the Aveksa Application: Exceptions Manager entitlement from a user was completed but the access was not removed from the user.
Cause
The fact that the change request shows the access has been removed when it has not been removed has been reported in engineering ticket ACM-103280.
Resolution
This issue is being investigated by the Engineering team in order to provide a permanent resolution in a future release.
Workaround
For example, to resolve the example presented in this RSA Knowledge Base Article:
- Navigate to Users > Users > {user name} > Access tab
- Click on the i icon for the Application : Exceptions Manager entitlement.
- In the pop-up dialog box, click on the Security Scope drop-down.
- Note the Name(s) listed. These are the Applications and/or Directories to which the user is assigned as a Violation Manager.
- Navigate to Resources > Applications/Directories > {Application name} > Edit.
- Scroll to the bottom of the page.
- Click on Violation Manager and change the existing Violation Manager to a different user.
- Click OK > OK to save your changes.
- Navigate to the Users > Users > {user name} > Access tab and note that the Application:Exceptions Manager entitlement has been removed. If the user has no other Aveksa entitlements, the Aveksa application account associated with that user is also removed.
Related Articles
How to remove entitlements of a decommissioned application from user access in RSA Via Lifecycle and Governance 74Number of Views Unable to remove account from group through a review in RSA Identity Governance & Lifecycle 61Number of Views Unable to remove privileges for an RSA Via Governance and Lifecycle user 83Number of Views How to use name locking with RSA ACE/Agent 5.0 API 69Number of Views How to remove all user data stored in the RSA Identity Governance and Lifecycle application database 765Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?