RSA Identity Governance & Lifecycle requests stuck in "Pending Verification" state when using Entitlement Requires Account feature
4 years ago
Originally Published: 2018-09-26
Article Number
000041140
Applies To
RSA Product Set: Identity Governance & Lifecycle
RSA Version/Condition: 7.0.2, 7.1.0
Issue
RSA Identity Governance & Lifecycle requests are stuck in a Pending Verification state and the Account value shows with a temporary account name in the format {nnnnnn} account on {Application Name}.   This occurs when the request contains an entitlement for a user where no account currently exists and the application is configured with the Entitlement Requires Account setting set to True.   The change request details page shows that the account creation step is Completed.  The Entitlement (Entitlement, Group, or Role) is also completed, but the request does not move from"Pending Verification to Verified.
User-added image
Cause
This issue may occur if the directory or application is configured with the Entitlement Requires Account setting but there is no account template associated with the directory or application.   The request is unable to create the account name for the pending request and without a valid account name the entitlement cannot be verified during the collection.
Resolution
Ensure that a valid account template is associated with the directory or application.   From the Resources menu, select the directory or application and then click the Requests tab.  Click the Edit Account Template Associations button and select an account template. 
 
User-added image
 
If you are using the Entitlements Require Account feature you must select an account template that has a valid Pending Account Parameters defined.
 
User-added image
Notes
The system will warn you if you attempt to set the Entitlement Requires Account without a valid account template

Entitlements Require Account cannot be set to YES if there are no account templates with a valid "Name" pending account parameter.
 
User-added image