How user selection and custom account attribute filters work in User Access Reviews in RSA Identity Governance and Lifecycle
Originally Published: 2018-01-10
Article Number
Applies To
RSA Version/Condition: All
Issue
The filter does not seem to work correctly for all users.
In the example below you can see the review result is including one user whose Account Status=LOCKED. Ideally, the user should not have been included in the review result.
Resolution
As shown below the user molly is included in the review because she has an account in another business source whose status is not LOCKED.
One option here is to use an advanced expression to select the users to include that matches the business source(s) used in the access step:
users.id in accounts (accounts."Account Status"<>'LOCKED' and accounts."Application Name"='DAMS') .
After using the advanced filter you can see the account is excluded from review result.
Notes
Related Articles
The workpoint log has daily occurrences of ORA-02049: timeout: distributed transaction waiting for lock errors in RSA Id… 319Number of Views How users are selected for reviews that are triggered by rules in RSA Identity Governance & Lifecycle 25Number of Views How business source filtering works in an account access and ownership review in RSA Identity Governance & Lifecycle 46Number of Views Reviews create change requests for access removed/deleted access outside of reviews in RSA Governance and Lifecycle 19Number of Views Account summary table export includes the HTML tags that construct the account mapping button in RSA Identity Governance &… 38Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?