Create Account fails if previous Create Account is pending in RSA Identity Governance & Lifecycle
Originally Published: 2019-08-13
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
Issue
The RSA Identity Governance & Lifecyle Entitlement Requires Account feature is a feature that automatically creates an account when adding an entitlement related to the account and the account does not exist. For example, when adding a User to a Group, this feature will create the account for the user before adding the account to the group. The first time an entitlement is requested, the system will identify that an account does not exist and will automatically create the account. For subsequent entitlements there is no need to create the account.
If there is a problem with the initial request that creates the account, subsequent change requests for entitlements that require that account may fail.
Cause
- before clicking on the Finish button, the requester closes out of the browser or navigates away from the submission page through anything other than the Cancel or Back buttons, or
- the browser times out before the request has been completed (i.e before the Finish button has been pressed.)
The existence of this pending account prevents future entitlement requests because the account is required and yet does not actually exist but looks like it exists due to its pending status.
This is a known issue reported in engineering ticket ACM-89679.
Resolution
- RSA Identity Governance & Lifecycle 7.0.2 P14
- RSA Identity Governance & Lifecycle 7.1.0 P07
- RSA Identity Governance & Lifecycle 7.1.1 P02
To handle this issue, a new section in the RSA Identity Governance & Lifecycle user interface has been added called Pending Submissions under Requests > Requests, which will display the change requests which were left in the Pending Submission State.
New change requests for access are prevented from being generated if requests already exist in the Pending Submission State for the account associated with the requested access.
The Request Form will not allow the user to submit the request and instead will display the following warning message under Dependencies:
The changes for the account ##### depends on the request XXXXX which was not successfully submitted. Please cancel the request before taking further actions by navigating to Pending Submissions tab.
Notes
Related Articles
Activity Node Excludes Previous Approvers Without Exclusion Settings in RSA Governance & Lifecycle 3Number of Views Attribute Change Rule reverts to a previous version after making changes in RSA Identity Governance & Lifecycle 23Number of Views What is Schema.Mitigator.pruneAttributes in SilverTail v4.x 7Number of Views Can an upgraded RSA SecurID Access Identity Router be rolled back to a previous version? 66Number of Views How to upgrade to Sentry CA 3.6 from a previous version of Sentry CA. 3Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?