Provisioning/Termination Rule does not create change requests to revoke entitlements if the rule also disables and/or deletes accounts in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-18
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
Issue
This occurs when the following Rule Actions are defined:
- Disable accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Disable accounts (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
For example the following Provisioning - Termination Rule defines all three actions:
If a Provisioning - Termination Rule is defined to only revoke user entitlements, a change request to revoke the entitlements is created as expected.
Cause
This issue occurs when a user has accounts. If the user does not have any accounts and only has user entitlements, then a change request to revoke entitlements is created as expected.
Resolution
- RSA Identity Governance & Lifecycle 7.0.2 P13
- RSA Identity Governance & Lifecycle 7.1.0 P09
- RSA Identity Governance & Lifecycle 7.1.1 P03
- RSA Identity Governance & Lifecycle 7.2.0
Related Articles
RSA Identity Governance and Lifecycle Provisioning -Termination rule is not generating change requests to revoke entitlements 82Number of Views RSA SecurID Pool setting in RSA Authentication Agent 5.3 for Web overrides cookie session 36Number of Views Empty Termination Change requests created for users that are deleted in RSA Governance & Lifecycle 12Number of Views Netskope Security Cloud - SAML Relying Party Configuration - RSA Ready Implementation Guide 16Number of Views Provisioning Termination rule is not generating change requests to disable accounts in RSA Identity Governance and Lifecycle 128Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?