Leaver Rule–Deprovision is not moving Disabled Accounts to the Disabled OU in RSA Governance & Lifecycle
Originally Published: 2025-06-29
Last Modified: 2025-10-24
Article Number
Applies To
- RSA Governance & Lifecycle 8.0
Issue
The Leaver rule – Deprovision process is does not move disabled Accounts to the Disabled OU. While the Account is correctly disabled, it remains in the original OU instead of being placed in the Disabled OU. This is evident in the below Change Request, generated by the Rule:
Cause
A new Custom Parameter, EnableAddEntitlementToTerminatedUsers, was introduced in version 8.0.0 P01, this was not applied in the environment. The Custom Parameter allows Change Request creation for terminated Users.
Resolution
Update the value of the custom parameter from Admin > System > Settings:
- EnableAddEntitlementToTerminatedUsers to true.
Certain behavior will now be allowed for Terminated Users from the application, including creating Change Requests.
Related Articles
How to Include or Exclude an Active Directory OU from the Microsoft LDAP directory on RSA Authentication Manager 8.x 105Number of Views How to publish CA certificate and user certificate under the same OU ? 8Number of Views Publishing certificates with multiple OU values 14Number of Views RSA enVision How to move collected devices logs using lsmaint utility 29Number of Views Logs not collected from Widows XP desktops/laptops if in the same domain as windows servers 9Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?