RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
You have a fine-grained role review which allows role reviewers the ability to remove members and entitlements from roles. It also allows role reviewers the ability to delete roles and all their associated members and entitlements. While modifying role content is okay, you do not want reviewers requesting that roles be deleted.
In this case to prevent role deletion from a review, a Cancel Change Request node was added to the fulfillment workflow that processes role requests. If a role reviewer requested a role be deleted, the resulting change request would delete the role. The Cancel Change Request node would then attempt to add back the role by reverting the changes already made (that is, the role was deleted). Adding the role back was a manual activity. The problem is that when the manual change was made, the following error would occur and the role was not added back.
[Test1] have been deleted. Please cancel the change request.
Further, because this action was not allowed, the change request could not be completed.
Note the fulfillment workflow shown below. The workflow has a decision node to verify if the reviewer is deleting the entire role. If so, then it is passed to the Cancel Change Request node with Event Type of Cancel entire request and revert completed changes.
Below is the change request created for one such change. There are two role changes created, one is to Remove the entire role as per the reviewer activity and the other one is to Add the deleted role back by cancelling the request and reverting the changes (as defined by the Event Type setting).
Note the Add Role is in a Pending Action state which requires a manual activity. When the assigned user goes to complete the Add Role manual activity, the above error occurs.
Related Articles
Change Request Cancel and Revert is not Always Reverting Indirect Items in RSA Identity Governance & Lifecycle 13Number of Views How to stop RSA Via Lifecycle & Governance (IMG) review items from reverting back to the default state after a change requ… 104Number of Views "Invalid column index" error in RSA Identity Governance and Lifecycle review "Total Entitlements not in Review" 41Number of Views LDAP sync job cannot delete RSA ACE/Server user marked for deletion 19Number of Views Cancel change request workflow node defined with the 'Move request to error state' option leaves the workflow in a permane… 99Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x