Remove groups from multiple disabled Accounts fails with error: "Expected 1 account associated with the ChangeRequestItem. There were 2" in RSA Identity Governance and Lifecycle
Originally Published: 2017-10-05
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 6.9.1, 7.0.1, 7.0.2
Issue
The CR Item fails with the following error:
Exception while processing the automated request for item Expected 1 account associated with the ChangeRequestItem. There were 2. CRI=[com.aveksa.server.core.cr.ChangeRequestItem@4ac2701f[reqID=13,itemID=43,stateStr=PZ,fullOperationStr=RemoveUserFromUserGroup,operandID=68,operandName=Helmy, Mostafa,operandDcId=63,operandAppId=<null>,description=<null>,valueTypeStr=UG,valueID=93,value2ID=<null>,valueName=TestGroup,valueAppId=41,value2AppId=<null>,valueDcId=62,value2DcId=<null>,watchId=49,watchToken=266:WPDS-26:WPDS-264:WPDS-0,affectedUserId=68,additionalData=<map/>]]
Account List:
Account{id=3, name='Mostafa.Helmy', applicationId=41, adcId=62, lastLoginDate=null, isDisabled='1', isLocked='0', creationDate=2017-04-07 19:09:52.0, lastCollectedDate=2017-04-11 14:42:55.0, addState='NotPending', removeState='NotPending', orphanedDate=null, isOrphaned='N', isDeleted='N', deletionDate=null, accountCollectorName='Active Directory ADC', applicationName='Active Directory', applicationRawName='Active Directory', isShared='y', isService='FALSE', userAccountMappings=[UserAccountMapping{id=15, accountId=3, accountName='Mostafa.Helmy', userId=68, isUserDeletedStr='n', adcId=62, createdBy=null, deletedBy=null, comments='null', stateStr='VA', collectedDate=null, creationDate=2017-04-07 19:09:52.0, lastCollectedDate=2017-04-11 14:42:55.0, deletedDate=null, addStateCode=0, addState=null, removeStateCode=0, removeState=null}], derivedFromType='null', derivedPath='null', expirationDate='null', guid='6d001ad5-d6bd-4d28-93d2-865ce92ce350', objectSid='null'},
Account{id=14, name='Mostafa.Helmy.2', applicationId=41, adcId=62, lastLoginDate=null, isDisabled='1', isLocked='0', creationDate=2017-04-07 19:12:48.0, lastCollectedDate=2017-04-11 14:42:55.0, addState='NotPending', removeState='NotPending', orphanedDate=null, isOrphaned='N', isDeleted='N', deletionDate=null, accountCollectorName='Active Directory ADC', applicationName='Active Directory', applicationRawName='Active Directory', isShared='y', isService='FALSE', userAccountMappings=[UserAccountMapping{id=47, accountId=14, accountName='Mostafa.Helmy.2', userId=68, isUserDeletedStr='n', adcId=62, createdBy=null, deletedBy=null, comments='null', stateStr='VA', collectedDate=null, creationDate=2017-04-07 19:12:48.0, lastCollectedDate=2017-04-11 14:42:55.0, deletedDate=null, addStateCode=0, addState=null, removeStateCode=0, removeState=null}], derivedFromType='null', derivedPath='null', expirationDate='null', guid='6fbd6a34-d66e-4c62-b9b2-10adeba69788', objectSid='null'}, exception is: {1}
Steps to Reproduce:
- User has two AD accounts.
- These two accounts have access to an AD group.
- The accounts are then disabled in AD and collected.
- When a change request is created to remove the groups from the access tab of the user, note that the “submit Request” button has only 1 change instead of 2.
Comment of the item shows the error:
Cause
Resolution
Related Articles
Entitlement(app-role/group/ent) revocation request with multiple accounts in an application fails with error:"Expected 1 a… 49Number of Views View an Agent Associated with a RADIUS Profile 10Number of Views How to configure RSA Mobile return email address 5Number of Views Does RCM handle all special characters in email address allowed per the RFC? 12Number of Views Plus (+) characters changed to (%2b) in email text sent from Workflow Email Nodes in SecurID Governance & Lifecycle 25Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?