Many customers observe this notification under the user management page in CAS
CAS includes an automated cleanup mechanism designed to keep the cloud database optimized by removing users who were synced to the service but never actually used it. A background process periodically evaluates all users and identifies those who meet a strict set of conditions that classify them as inactive.
A user becomes eligible for cleanup when all of the following criteria are true:
-
The user has never authenticated to CAS.
-
The user has not been synced for more than 30 days.
-
The user has no SMS or Voice overrides configured.
-
The user has no FIDO authenticators or registered devices.
-
The user has no assigned SecurID tokens.
-
The user has no emergency token codes.
-
The user has no offline emergency token codes.
This is part of the user cleanup process running in the background, designed to save the CAS DB storage. These users can be synced back to the cloud through bulk or JIT sync, since they have not done any authentications with the cloud and never had authenticators registered, and deleting them will not result in any data loss.
This is only applicable for AD users.
Related Articles
Cleanup WTD Incidents table (postgreSQL) 26Number of Views Terminated users are not displayed while manually mapping accounts in RSA Identity Governance & Lifecycle 7.1.0 45Number of Views Managing User Accounts 21Number of Views Locked User Accounts 73Number of Views RSA Governance & Lifecycle Recipes: Overview - User Accounts 27Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)