Partially orphaned accounts occur in RSA Identity Governance & Lifecycle when the ADC defines multiple user resolution attributes from the same target collector
Originally Published: 2019-05-01
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0
Issue
Partially orphaned accounts are created after Unification. In the example below, note that UserC3 is not displayed as an orphaned account, yet it is not mapped to any user which is the definition of an orphaned account.
Cause
As an example, an IDC collects User Id, Email Address, and Department. An ADC collects AccountName. Three User Resolution rules are defined on these IDC attributes in the ADC definition:
After running the IDC, Unification and ADC, the AccountName resolves to the User Id and correctly maps the users.
If one of the user attributes other than the User Id is modified in the IDC, the problem occurs. In this case, the email address for UserC3 was modified. After running the IDC and Unification, the account is left partially orphaned:
Resolution
Workaround
Related Articles
RSA Governance & Lifecycle Recipes: Chart - Application - Application Orphan Summary 10Number of Views RSA Governance & Lifecycle Recipes: Report - AD Orphan Accounts 25Number of Views RSA Governance & Lifecycle Recipes: Overview - Exploded Entitlements 9Number of Views RSA Governance & Lifecycle Recipes: Review Results 12Number of Views RSA Governance & Lifecycle Recipes: Overview - Roles 16Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?