How to configure the RSA Identity Governance and Lifecycle system to prevent users from requesting exceptional access
Originally Published: 2017-06-13
Article Number
Applies To
RSA Version/Condition: All
Issue
Tasks
- First define the exceptional access:
- Create an SOD rule that defines the exceptional access:
Rules > Definitions > Create New Rule > Type: Segregation of Duties
- Process the rule.
- Second, define who can and cannot request the exceptional access:
- Go to Requests > Configuration -> Submission tab -> Edit Settings.
- Under Violations there are three options:
By default, these options are not checked. This means anyone can request exceptional access and submit the request. To prevent users from requesting exceptional access, the first two options need to be defined.
- The first option Show violations to the specified requestors determines who will see if their requested access creates a violation. Any user meeting this criteria will see a warning if they request exceptional access:
- The second option Requests with violations can be submitted by requestors determines who is allowed to request exceptional access. Any user that does NOT meet this criteria AND that meets the criteria of the first option will be prevented from submitting the request:
Resolution
Related Articles
"A PIN is required for this token" error on RSA Authentication Manager 8.x when requesting an RSA SecurID software token f… 32Number of Views 'No certificate request was made' error when requesting a certificate on a smart card of SID800 against RSA Certificate Ma… 24Number of Views Unexpected error during command com.rsa.ucm.request.AddSelfServiceRequestCommand execution when requesting token via-Authe… 193Number of Views XudaInstanceOf failed to get xuda_cert_req object! result = 48 12Number of Views Program Error: 'req-authorize.xuda: Line 518: [XrcNOTFOUND] unable to locate requested member or object. Unable to sign ce… 18Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?