RSA Version/Condition: 7.1.0, 7.1.1
When using the Entitlements Require Account feature, change requests that require an account will create an account first and then add the entitlement to the account. In some instances the Create Account line in the change request is able to create the account but the request does not add the entitlement to the account.
The change request will remain in the Fulfillment Phase state and the change request details under the Status column will show the following states for the line items:
- Create Account - Pending Action - New account creation for user triggered automatically by dependent change item.
- Add Account to Group - Waiting On Dependencies - Indirect change item.
This issue may occur if the AFX connector is using the connector Command Output Parameters feature to map the output of the Create Account connector capability to a Parameter Name used by the Add Account to Group connector capability. This is a known issue in RSA Identity Governance & Lifecycle 7.1.x where the command output parameter mapping does not update the value of the parameter correctly.
- RSA Identity Governance & Lifecycle 7.1.0 P06
- RSA Identity Governance & Lifecycle 7.1.1 P01
The fix is to allow the value of the variable mapped in the Command Output Parameters to be passed to the next step in the AFX request.
Related Articles
Auto generated revocation requests Stuck in Fulfillment Phase with AFX errors in connector logs If any Change Item rejecte… 157Number of Views Workflows stuck in AFX fulfillment and/or Provisioning nodes in RSA Identity Governance & Lifecycle 550Number of Views Change Request Revert Workflow stuck in Canceling state in RSA Identity Governance and Lifecycle 102Number of Views RSA Identity Governance & Lifecycle Access Fulfillment Express (AFX) Change Requests that depend on Entitlements Require A… 410Number of Views Change requests provisioned by AFX remain in "pending action" or "pending verification" in RSA Governance & Lifecycle 188Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide