How to remove the Edit Users button from Account Review Results in RSA Identity Governance & Lifecycle
2 years ago
Originally Published: 2015-04-14
Article Number
000067590
Applies To
RSA Product Set: RSA Identity Governance & Lifecycle
RSA Version/Condition: 7.0.x, 7.1.x, 7.2.x
 
Issue
Account Reviews in RSA Identity Governance & Lifecycle (Reviews > Definitions > Review Type: Account Access and Ownership) allow reviewers to map and unmap user accounts during the Review. This feature is enabled by default with an Edit Users button in the Review Results for each account being reviewed. This RSA Knowledge Base Article explains how to remove the Edit Users button from Review Results so that reviewers may not modify user account mappings.

EXAMPLE

In the example below, note the Edit Users button when expanding the drop-down menu next to a specific account to be reviewed. (Reviews > Results > {Review Result Name} > Review Items button > {pick a tab} > show all items).
 
User-added image

 
Resolution
To remove the Edit Users button from Account Reviews, add a custom parameter called AccountUserMappingDisabled.
  1. Go to Admin > System > Edit > scroll down to Custom.
  2. Add AccountUserMappingDisabled to the first field and true to the second field and Save.
  3. The word custom will be prefixed to the parameter name:
User-added image

This change takes effect immediately and does not require an application restart. This change effects current Review Results and all future Review Results. Below is the same Review Result as above. Note with the parameter set, the Edit Users button no longer displays.
User-added image