RSA Via Lifecycle and Governance 6.9.1 P06 User Access Review includes indirect entitlements of users
Originally Published: 2016-06-15
Article Number
Applies To
RSA Version/Condition: 6.9.1 P06
Issue
The example below shows the indirect entitlement getting pulled in user access review
- A technical role named Test Roles is created:
- The AD group entitlements of Test Roles is shown below:
3. Create a Business Role using the technical role created above as its entitlements:
- Add a user to the business role:
- Navigate to Users > Users.
- Search for the user created in step 1 above
- Click on the Access tab. It shows the business role crated above as its direct entitlement
- The Users Access tab shows the AD group entitlements of the technical role created above (i. e., Test Roles), which is a direct Entitlement of Business Role as its indirect entitlements.
- Run a user access review using the conditions shown below in the User Selection tab and the Contents tab.
- The review result shows all three groups of the user's indirect entitlements. The user access tab should include only direct entitlements, but here you will see indirect entitlements are also pulled.
Resolution
Related Articles
How to interpret the RSA Identity Governance & Lifecycle User Access Review User Entitlement Coverage report. 40Number of Views Creating a custom attribute and reporting on it in RSA Authentication Manager 8.2 SP1 or later 16Number of Views How to create an Aveksa Statistics Report (ASR) in RSA Identity Governance & Lifecycle 208Number of Views RSA MFA Agent 2.0 for Epic Hyperdrive Installation and Administration Guide 140Number of Views A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer ex… 49Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?