RSA Identity Governance and Lifecycle Access Fulfillment Express (AFX) command output parameters do not work if the attribute name contains spaces
Originally Published: 2017-01-06
Article Number
Applies To
RSA Version/Condition: 7.0.0, 7.0.1
Issue
Steps to reproduce the issue
- Setup an Active Directory as a directory.
- Under Requests link any simple Account template with a pending parameter Name and choose Entitlements require an Account.
- Setup an AD AFX connector.
- Under Create Account capability, add a command output parameter to read the distinguishedName and map it to any attribute that has spaces in its name (for example: External ID):
- Now in the capability Add Account to Group, use the same attribute used above as the "Account" Parameter.
- Create a change request to add an AD Group to any user that does not yet have an AD account.
Expected behavior
- CR created with two items, create account then add group to account. Both items are fulfilled by AFX and then wait for verification
Actual behavior
- CR created with two items, create account then add group to account. Create account is successful, but Add group to account fails.
Cause
Resolution
Workaround
Access the RSA Identity Governance and LIfecycle portal. Go to Admin > Attributes and remove the space in the attribute name used in the AFX output parameter or use the parameter that doesn't contain any spaces.
An example of a scenario where attribute name has no space follows:
1. Choose another attribute that does not have any spaces in its name and use it as the output parameter (for example, DN).
- Create another similar CR. This time changes will be fulfilled as expected.
Related Articles
Security scope does not display report names associated with Aveksa Report Result entitlements in RSA Identity Governance … 44Number of Views RSA Identity Governance and Lifecycle NullPointerException when rules associated with Attribute Synchronization run 162Number of Views Unauthorized change rule triggered although change request for add access has passed approval phase in RSA Identity Govern… 50Number of Views Attribute Synchronization sometimes updates attributes with attribute variable names instead of attribute values in RSA Id… 85Number of Views Local Entitlement stays in pending verification state in RSA Governance & Lifecycle 107Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process
Don't see what you're looking for?