Provisioning/Termination Rule does not create change requests to revoke entitlements if the rule also disables and/or deletes accounts in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-18
Last Modified: 2023-10-06
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
Issue
This occurs when the following Rule Actions are defined:
- Disable accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Disable accounts (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
For example the following Provisioning - Termination Rule defines all three actions:
If a Provisioning - Termination Rule is defined to only revoke user entitlements, a change request to revoke the entitlements is created as expected.
Cause
This issue occurs when a user has accounts. If the user does not have any accounts and only has user entitlements, then a change request to revoke entitlements is created as expected.
Resolution
- RSA Identity Governance & Lifecycle 7.0.2 P13
- RSA Identity Governance & Lifecycle 7.1.0 P09
- RSA Identity Governance & Lifecycle 7.1.1 P03
- RSA Identity Governance & Lifecycle 7.2.0
Related Articles
Termination rule sometimes fails to create change requests to disable accounts in specific applications in RSA Identity Go… 135Number of Views Change Items depends on Account Creation marked as 'Rejected' If the Create Account Request 'Cancelled' without showing th… 4Number of Views How the Pending Revoke category functions in the default reviewer interface style of the User Access Review in RSA Identit… 64Number of Views Create Account fails if previous Create Account is pending in RSA Identity Governance & Lifecycle 110Number of Views How to access the Run Database Logs in RSA Identity Governance & Lifecycle 62Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?