Provisioning/Termination Rule does not create change requests to revoke entitlements if the rule also disables and/or deletes accounts in RSA Identity Governance & Lifecycle
Originally Published: 2019-04-18
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0, 7.1.1
Issue
This occurs when the following Rule Actions are defined:
- Disable accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
- Disable accounts (excludes shared and service accounts)
- Delete accounts (excludes shared and service accounts)
- Revoke user entitlements (excludes shared and service accounts)
For example the following Provisioning - Termination Rule defines all three actions:
If a Provisioning - Termination Rule is defined to only revoke user entitlements, a change request to revoke the entitlements is created as expected.
Cause
This issue occurs when a user has accounts. If the user does not have any accounts and only has user entitlements, then a change request to revoke entitlements is created as expected.
Resolution
- RSA Identity Governance & Lifecycle 7.0.2 P13
- RSA Identity Governance & Lifecycle 7.1.0 P09
- RSA Identity Governance & Lifecycle 7.1.1 P03
- RSA Identity Governance & Lifecycle 7.2.0
Related Articles
Termination rule sometimes fails to create change requests to disable accounts in specific applications in RSA Identity Go… 132Number of Views Termination rule not generating a change request to disable the manually mapped accounts in RSA Identity Governance & Life… 41Number of Views RSA Identity Governance and Lifecycle Provisioning -Termination rule is not generating change requests to revoke entitlements 81Number of Views Provisioning Termination rule is not generating change requests to disable accounts in RSA Identity Governance and Lifecycle 127Number of Views Check Point VPN Clients Discovering as Enforcement Points 23Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?