Provisioning/Termination Rule does not create change requests to revoke entitlements if the rule also disables and/or deletes accounts in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-18
Last Modified: 2023-10-06
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
Issue
This occurs when the following Rule Actions are defined:
- Disable accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Disable accounts (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
For example the following Provisioning - Termination Rule defines all three actions:
If a Provisioning - Termination Rule is defined to only revoke user entitlements, a change request to revoke the entitlements is created as expected.
Cause
This issue occurs when a user has accounts. If the user does not have any accounts and only has user entitlements, then a change request to revoke entitlements is created as expected.
Resolution
- RSA Identity Governance & Lifecycle 7.0.2 P13
- RSA Identity Governance & Lifecycle 7.1.0 P09
- RSA Identity Governance & Lifecycle 7.1.1 P03
- RSA Identity Governance & Lifecycle 7.2.0
Related Articles
Termination rule sometimes fails to create change requests to disable accounts in specific applications in RSA Identity Go… 135Number of Views Provisioning Termination rule is not generating change requests to disable accounts in RSA Identity Governance and Lifecycle 131Number of Views Create Account fails if previous Create Account is pending in RSA Identity Governance & Lifecycle 115Number of Views Change Items depends on Account Creation marked as 'Rejected' If the Create Account Request 'Cancelled' without showing th… 4Number of Views Unable to create an account in Active Directory with a custom objectClass in RSA Governance & Lifecycle 36Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?