Correct Termination Rule behavior in RSA Identity Governance and Lifecycle 7.x
Originally Published: 2017-05-30
Article Number
Applies To
RSA Version/Condition: 7.x
Issue
- What is the correct behavior on the part of the Termination Rule?
- What happens to all the users whose attribute is changed to IS_TERMINATED=1/yes status during one of the collection periods in previous runs?
Resolution
This behavior is by design.
NOTE - This behavior of Termination Rule is by design irrespective of the actions taken. Actions such as Disable/Delete Account do not have any affect on this behavior and are shown here only as an example of Rule configuration with actions.
For example, let's say you have created a Termination Rule with the following configuration (where no filter is used on a condition):When you run an Identity Data Collector (IDC) that collects users whose termination status is changed (Is_Terminated=1), and then run the Termination Rule (Provisioning-Termination) for the first time (with or without filter), the rule will identify the terminated users as follows:
The result above shows that the rule has identified nine terminated users:
Processing Summary:
- Number of terminated users found:9
- Number of deleted users found:0
After this, if you update the Rule Definition with the condition updated as Is_terminated=yes (shown below) and run the same rule again, users will not be identified as terminated.
Processing Summary:
- Number of terminated users found:0
- Number of deleted users found:0
These users will not be identified as terminated, since it is a different/next run and does not reflect as the updated status for "Is_terminated" attribute.
Related Articles
Change in the review behavior while using "Include group memberships that are entitlements of their assigned global roles"… 36Number of Views RSA Governance & Lifecycle Recipes: Rule Telemetry - Processing (Running Total) 9Number of Views RSA Identity Governance and Lifecycle 7.0.1 rule pre-processing taking longer time to complete 57Number of Views Slow INSERT statement executing from the SoD_Rule_Pkg in RSA Identity Governance & Lifecycle 90Number of Views Termination rule not generating a change request to disable the manually mapped accounts in RSA Identity Governance & Life… 41Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?