How user selection and custom account attribute filters work in User Access Reviews in RSA Identity Governance and Lifecycle
Originally Published: 2018-01-10
Article Number
Applies To
RSA Version/Condition: All
Issue
The filter does not seem to work correctly for all users.
In the example below you can see the review result is including one user whose Account Status=LOCKED. Ideally, the user should not have been included in the review result.
Resolution
As shown below the user molly is included in the review because she has an account in another business source whose status is not LOCKED.
One option here is to use an advanced expression to select the users to include that matches the business source(s) used in the access step:
users.id in accounts (accounts."Account Status"<>'LOCKED' and accounts."Application Name"='DAMS') .
After using the advanced filter you can see the account is excluded from review result.
Notes
Related Articles
How business source filtering works in an account access and ownership review in RSA Identity Governance & Lifecycle 46Number of Views An option to edit the display buttons of the Review and Remove buttons in Group and Role Reviews has been added in RSA Ide… 42Number of Views Groups are unassigned in User Access Review for RSA Identity Governance and Lifecycle 38Number of Views How users are selected for reviews that are triggered by rules in RSA Identity Governance & Lifecycle 25Number of Views Reviews create change requests for access removed/deleted access outside of reviews in RSA Governance and Lifecycle 19Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?