Existing Role memberships later granted through Parent Roles are not revoked when the Role memberships are removed from the Parent Role in RSA Identity Governance & Lifecycle
Originally Published: 2020-09-01
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 7.1.1, 7..2.0
Issue
For example, if a user has direct access to a Technical Role and is later granted membership to a Business Role that has the Technical Role as an entitlement, their access to the Technical Role is now explained via their membership to the Business Role. If the Technical Role entitlement is removed from the Business Role, the user should lose access to the Technical Role unless they belong to one or more other Business Roles that have that same Technical Role as an entitlement. Once they do not belong to any Business Role that explains their right to be a member of the Technical Role, they are no longer entitled to be a member of the Technical Role regardless of how they originally acquired that access.
EXAMPLE:
- Create Technical Role 1 with no entitlements.
- Add user Cherry Blossom as a member of Technical Role 1.
- Cherry Blossom now has direct access to Technical Role 1.
- Create Business Role 1.
- Add Technical Role 1 as an entitlement to Business Role 1.
- Add user Cherry Blossom as a member of Business Role 1.
- Now Cherry Blossom's access to Technical Role 1 is explained by her membership to Business Role 1.
- The problem occurs if Technical Role 1 is removed as an entitlement from Business Role 1. In this case Cherry Blossom should lose the access to Technical Role 1 but she does not.
Cause
Resolution
- RSA Identity Governance & Lifecycle 7.1.1 P07
- RSA Identity Governance & Lifecycle 7.2.0 P02
Related Articles
RSA Identity Governance and Lifecycle 7.0.1 rule pre-processing taking longer time to complete 57Number of Views Slow INSERT statement executing from the SoD_Rule_Pkg in RSA Identity Governance & Lifecycle 114Number of Views Z: Need to Finish - Multiple users showing in role history instead of person who applied changes 4Number of Views RSA Identity Governance & Lifecycle Imported Roles do not show entitlements on Users 89Number of Views Attribute change rule creating duplicate change items for users having more than one account with same entitlement in an a… 35Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?