Add entitlements table shows inconsistent results when the Role Set Policy is set to 'Deny entitlements not matching the entitlement rule' in RSA Identity Governance & Lifecycle
Originally Published: 2016-08-31
Last Modified: 2022-06-20
Article Number
Applies To
RSA Version/Condition: 7.0.1
Issue
Below are two examples of when this issue may occur.
Example 1:
- Create a Role Set named TestRoleSet. (Roles > Role Sets > Create Role Set)
- Set the Policy to Deny entitlements not matching the entitlement rule (Roles > Role Sets > TestRoleSet > Policy tab)
- Create an entitlement membership rule for the Role Set to unifiedents."Business Unit Id"=1. (Roles > Roles Sets > TestRoleSet > Policy tab > Membership Rule)
- Go to Roles > Roles > Create/Discover > Create role and create TestRole1 role in Role Set TestRoleSet.
- Go to the Entitlements tab for TestRole1 (Roles > Roles > TestRole1 > Entitlements tab) and click on Add Entitlements.
- It is expected that matching entitlements will be displayed, as per the entitlements rule:
What happens is that:
- Either no data is displayed in the table:
- Or an Error - is displayed in the table.
Example 2:
- Set the TestRoleSet entitlement membership rule to unifiedents.'Business Source"='Application Name'. (Roles > Roles Sets > TestRoleSet > Policy tab > Membership Rule) where Application Name has 31 entitlements.
- Go to the TestRole1 entitlements tab (Roles > Roles > TestRole1) and click on Add Entitlements.
- It is expected that the entitlement table should display the data per the defined rule. What happens is that the count is displayed as 31 but the records are displayed as Error -.
Cause
Resolution
- RSA Identity Governance & Lifecycle 7.0.1 P02
- RSA Identity Governance & Lifecycle 7.0.
Related Articles
How to reset table views to their original factory-set (OOTB) defaults in RSA Identity Governance & Lifecycle 33Number of Views Membership Rule Or Entitlement Rule under Roles show the Display Description and full code condition for Role Set in RSA G… 2Number of Views No enum constant com.aveksa.server.report.Report.SaveAsType.XLS reported in RSA Identity Governance & Lifecycle 32Number of Views How to update an Active Directory Account Attribute to have no value <not set> using an Active Directory AFX Connector in … 138Number of Views Exporting a set of One Time Tokencodes from RSA Authentication Manager Self-service Console 96Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to test RSA Identity Router (IDR) Secure Connector connectivity to the RSA ID Plus Cloud Access Service RSA SecurID Software Token for Microsoft Windows shows blank screen when asked to select a device where the token will be … RSA Governance & Lifecycle Generic Database Collector Guide RSA Authentication Manager 8.7 SP2 Administrator's Guide
Don't see what you're looking for?