How the Pending Revoke category functions in the default reviewer interface style of the User Access Review in RSA Identity Governance & Lifecycle
Originally Published: 2020-03-17
Last Modified: 2023-10-06
Article Number
Applies To
RSA Version/Condition: 7.1.x, 7.2.x
Issue
Using the new interface style allows reviewers to review items based on categories as defined under the Reviews > Definitions > {Name of user access review} > Analysis & Guidance tab. The purpose of this RSA Knowledge Base Article is to explain how the Pending Revoke category functions as it behaves slightly differently from the other categories.
Note: The complete Pending Revoke description in the above screenshot is:
The system identifies review items that are already pending revocation. Any identified items are listed in the "Pending Revoke" category. Note: Reviewers cannot perform any action on items that are pending revocation. Regardless of whether the Pending Revoke category is displayed in the Analysis and Guidance panel, all entitlements that are pending revocation are displayed within a review as completed and locked.
Resolution
The Pending Revoke category shows review items that already have a change request associated with them to revoke that access and always displays as 0 since they are considered completed and do not need to be reviewed. These items may be viewed by choosing the Completed drop-down menu option under Showing.
If accessing a user access review created prior to 7.1.0 or if using the Legacy reviewer user interface in 7.1.0 and above, pending revoke items can be reviewed and maintained or revoked. This ability to maintain/revoke pending revoke items has been removed in the new interface because the functionality makes no sense. If you revoke an already revoked item, it has no effect, and if you maintain a revoked item, it also has no effect because the pending revoke change request still exists and is not cancelled. As a result, by maintaining a pending revoked item, the reviewer is misled into thinking the items will be maintained. As a result, the ability to review such items no longer exists starting in 7.1.0. If any pending revoke items need to be maintained, the existing change request(s) need to be cancelled. The ability to view these items in the new interface without performing any action on them allows you to determine if there are any such requests that need to be cancelled without performing actions that have no effect.
Related Articles
How to interpret the RSA Identity Governance & Lifecycle User Access Review User Entitlement Coverage report. 41Number of Views Run history data is missing under the Custom Task workflow history tab in RSA Identity Governance & Lifecycle 37Number of Views RSA Identity Governance and Lifecycle review shows members with dashes for Maintain/Revoke action buttons 58Number of Views Access User Access Review not showing indirect entitlements associated with a role for RSA Identity Governance & Lifecycle… 97Number of Views Reassign user access review items in bulk by Application/Directory in RSA Identity Governance & Lifecycle 41Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?