Local entitlements belonging to roles are not consistently added to users in RSA Identity Governance & Lifecycle
Originally Published: 2019-08-28
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 7.1.0
Issue
- Roles have nested entitlements, or
- Members of roles are removed from a role and later added back to the same role.
- Create three Active Directory groups called Group1, Group2, and Group3.
- Make Group2 a member of Group1.
- Make Group3 a member of Group 2.
- These groups and subgroups are collected into an Active Directory Application in RSA Identity Governance & Lifecycle.
- Create three technical roles called Group1, Group2, Group3 (names same as groups). AD Group1 is a member of technical role Group1, AD Group2 is a member of technical role Group2 and AD Group3 is a member of technical role Group3.
- Create a business role called Business Role and initially add technical role Group3 as an entitlement to the business role. Add UserID1 to the business role.
- When changes are applied, a change request is created with two role changes, one account change, and two user changes. This is correct and expected behavior.
- Add technical role Group2 as an entitlement to the Business Role and apply changes.
- A change request is created with two role changes and one user change. The expected account change that would add account UserID1 to Group2 is missing.
Cause
Resolution
Related Articles
Group Entitlements are getting added to shared accounts in RSA Governance & Lifecycle 44Number of Views Entitlements are removed from or added to a Role when the Role Set is changed in RSA Identity Governance & Lifecycle 243Number of Views Role and Group Review Result behavior when members/entitlements are added to the underlying review items in RSA Identity G… 40Number of Views local user name attribute value not found in X.509 name 15Number of Views Active Directory AFX 'Disable/Enable an Account' connector capabilities do not update added parameters in RSA Identity Gov… 252Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?