How user selection and custom account attribute filters work in User Access Reviews in RSA Identity Governance and Lifecycle
Originally Published: 2018-01-10
Article Number
Applies To
RSA Version/Condition: All
Issue
The filter does not seem to work correctly for all users.
In the example below you can see the review result is including one user whose Account Status=LOCKED. Ideally, the user should not have been included in the review result.
Resolution
As shown below the user molly is included in the review because she has an account in another business source whose status is not LOCKED.
One option here is to use an advanced expression to select the users to include that matches the business source(s) used in the access step:
users.id in accounts (accounts."Account Status"<>'LOCKED' and accounts."Application Name"='DAMS') .
After using the advanced filter you can see the account is excluded from review result.
Notes
Related Articles
Custom URL is not rendering in the Review Instruction field and in the Review Email Body for RSA Via Lifecycle and Governance 37Number of Views RSA SecurID prompt does not appear when connecting with Remote Desktop Protocol RDP on Microsoft Windows Server 2019 with … 58Number of Views Add Authentication Source Access Rules 21Number of Views Change Requests sometimes complete but bypass both AFX and manual fulfillment and fail to modify the endpoint in RSA Ident… 163Number of Views Enable Email Reply Processing options differ in approval node in RSA Identity Governance & Lifecycle 40Number of Views
Don't see what you're looking for?