Leaver Rule–Deprovision is not moving Disabled Accounts to the Disabled OU in RSA Governance & Lifecycle
Originally Published: 2025-06-29
Article Number
Applies To
- RSA Governance & Lifecycle 8.0
Issue
The Leaver rule – Deprovision process is does not move disabled Accounts to the Disabled OU. While the Account is correctly disabled, it remains in the original OU instead of being placed in the Disabled OU. This is evident in the below Change Request, generated by the Rule:
Cause
A new Custom Parameter, EnableAddEntitlementToTerminatedUsers, was introduced in version 8.0.0 P01, this was not applied in the environment. The Custom Parameter allows Change Request creation for terminated Users.
Resolution
Update the value of the custom parameter from Admin > System > Settings:
- EnableAddEntitlementToTerminatedUsers to true.
Certain behavior will now be allowed for Terminated Users from the application, including creating Change Requests.
Related Articles
Publishing certificates with multiple OU values 12Number of Views How to Include or Exclude an Active Directory OU from the Microsoft LDAP directory on RSA Authentication Manager 8.x 89Number of Views How to publish CA certificate and user certificate under the same OU ? 7Number of Views Moving Users in an LDAP Directory 35Number of Views CUSD command generates a failure when moving tokens between security domains in RSA Authentication Manager Bulk Administra… 75Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?