Access User Access Review not showing indirect entitlements associated with a role for RSA Identity Governance & Lifecycle 7.x
Originally Published: 2018-10-30
Last Modified: 2022-06-20
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0
Issue
Only a portion of the user entitlements associated with a particular business source or application are shown even though the user is known to have other entitlements.
Cause
This is by design.
The Contents tab of the User Access Review can be used to filter entitlements by business source. Select the Contents tab and check the Filter business sources checkbox and then select the business sources using various criteria.
When filtering entitlements by business source and selecting an application name as the business source the review will only display direct entitlements. Indirect entitlements associated with a role will not be shown even if those entitlements are part of the application. This is because a role is a business source and entitlements associated with a role belong to the business source associated with the role set to which that that role belongs.
Resolution
For example, to include role based entitlements for the Aveksa application in addition to direct entitlements add the role set that contains the role as a business source.
This will allow the User Access Review to include roles on the review.
Notes
- The roles themselves will be reviewed not the indirect entitlements associated with the role.
- The role set may cover more than one business source or application.
Related Articles
How to interpret the RSA Identity Governance & Lifecycle User Access Review User Entitlement Coverage report. 41Number of Views RSA Identity Management and Governance account name not available when viewing the results of user access review 32Number of Views After refreshing a user access review, the business source values for roles (role sets) display as null in RSA Identity Go… 30Number of Views Run history data is missing under the Custom Task workflow history tab in RSA Identity Governance & Lifecycle 37Number of Views RSA Via Lifecycle and Governance 6.9.1 P06 User Access Review includes indirect entitlements of users 56Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Governance & Lifecycle 8.0.0 Installation Guide Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6
Don't see what you're looking for?