- Product: RSA Governance & Lifecycle
- Versions Affected: 7.1.0, 7.1.1, 7.2.0
- Resolved In: 7.1.1 P07, 7.2.0 P02
- Component: Role Management
Under the Roles > Roles > {role name} > General tab of the role the following message is displayed:
The aveksaServer.log file ($AVEKSA_HOME/wildfly/standalone/log/aveksaServer.log) shows the following ERROR level log message:
This is a normal state for a role that is completing the change request process that ensues from selecting Apply Changes. However, when this state never changes, the role is considered stuck and intervention is required.
RSA Identity Governance & Lifecycle cannot create the change request needed to complete the role commit because one or more entitlements or users referenced in the role change have been deleted from the system since the role was last committed.
After selecting Apply Changes on a role, the role becomes permanently stuck in an Applied or Applied
New state and does not progress to a Committed state. All further role management activities for the affected role are blocked.
The Role may get into this state if one (or more) of the entitlements or users being committed to the role has been deleted since the role was created.
For example:
- Add an entitlement to the role but do not Apply Changes to the role.
- Delete the entitlement from the endpoint and run a collection to remove the entitlement from RSA Identity Governance & Lifecycle.
- Apply Changes to the role.
The issue occurs because RSA Governance & Lifecycle is unable to create the change request for the entitlement required to modify the role since it has been deleted.
The permanent resolution for this issue is to apply the appropriate patch for your RSA Identity Governance & Lifecycle version. After patching, the system will handle deleted entitlement and user references gracefully during role commits — instead of failing silently and leaving the role stuck.
- Identify the patch applicable to your RSA Identity Governance & Lifecycle version:
Current Version Apply This Patch 7.1.1 RSA Identity Governance & Lifecycle 7.1.1 P07 7.2.0 RSA Identity Governance & Lifecycle 7.2.0 P02 NOTE: If you are running version 7.1.0, you must first upgrade to 7.1.1 before applying 7.1.1 P07. Contact RSA Support if you need guidance on the upgrade path.
- Download the patch for your version. See How to Download RSA Identity Governance & Lifecycle Patches for step-by-step download instructions.
- Apply the patch following the installation instructions included with the patch download.
- Verification: After the patch is applied and the system restarts, verify the fix is in effect:
- Navigate to Roles > Roles and open the affected role (or create a test role).
- Add or modify an entitlement or user membership and select Apply Changes.
- Navigate to Roles > Roles > (role name) > Members tab.
- Confirm that any deleted user or entitlement references are displayed with a strike-through and the following tooltip is shown:
This user has been deleted and will not be added as a member in the committed role. - Confirm the role commit completes successfully and the role transitions to a
Committedstate — without remaining stuck inAppliedorApplied New.
NOTE: If the role is currently stuck and patching cannot be applied immediately, see the Workaround section below for three techniques to recover the role to a Committed state without patching.
Workaround
⚠️ CAUTION: These are temporary workarounds that recover the stuck role to a Committed state without applying the patch. They do not prevent the issue from recurring. Apply the patch described in the Resolution section above to permanently resolve this issue.
Use the decision guide below to select the most appropriate technique for your situation:
| Technique | When to Use |
|---|---|
| Technique 1 — Cancel the Change Request | A change request was successfully created for the role change and is visible under Requests > Requests. Use this first — it is the least disruptive option. |
| Technique 2 — Delete the Role | No change request exists and the role cannot be recovered. Only use this if the role can be safely recreated. |
| Technique 3 — Force a Revert to Last Committed State | No change request exists, the role must be preserved, and the role has a previously committed state. Does not work for newly created roles that have never been committed. |
Technique 1 — Cancel the Change Request
NOTE: A change request is not always successfully created when this issue occurs. Before attempting this technique, confirm a change request exists under Requests > Requests for the affected role. If no change request is listed, proceed to Technique 2 or 3.
- Navigate to Requests > Requests in the RSA Identity Governance & Lifecycle UI.
- Search for and locate the change request associated with the stuck role change.
- Select the change request and click Cancel.
- Navigate to Roles > Roles and confirm the affected role has returned to a
Committedstate.
Technique 2 — Delete the Role
CAUTION: Deleting a role is permanent and irreversible. Deleting the role will trigger a change request to remove all entitlements and memberships associated with the role. Only proceed if you understand the full impact and the role can be safely recreated from scratch.
- Navigate to Roles > Roles.
- Locate the stuck role and select its checkbox in the left-hand column.
- From the Actions menu, select Delete.
- Confirm the deletion when prompted.
- Recreate the role as needed — ensuring Apply Changes is selected promptly after adding entitlements or users, before any referenced entitlements or users can be deleted.
Technique 3 — Force a Revert to Last Committed State
NOTE: This technique works only if the role has a previously committed state. It does not work for newly created roles that have never been committed. If the role was newly created and has no committed state, use Technique 2 instead.
CAUTION: This technique reverts all uncommitted changes made to the role since its last committed state — including the deleted entitlement or user reference that caused the issue, and any other uncommitted changes you may have made. You must re-apply any legitimate uncommitted changes manually after the revert completes.
- Navigate to Roles > Roles.
- Locate the stuck role and enable its checkbox in the left-hand column.
- From the Actions menu, select Add Entitlements.
- Add any arbitrary entitlement to the role.
(Expected result: the role status changes fromApplied NewtoChanged.) - From the Actions menu, select Revert Changes to Roles.
- Confirm the revert when prompted. The system will revert the role to its last committed state — removing the deleted entitlement or user reference, the arbitrary entitlement added in Step 4, and any other uncommitted changes.
- Navigate to Roles > Roles and confirm the role now shows a
Committedstate and the message "Additional changes cannot be made to this role..." is no longer displayed. - Re-apply any legitimate role changes that were reverted in Step 6.
Related Articles
When replacing an RSA SecurID software token with a new software token the token PIN is not carried over to the new token 611Number of Views RSA Authentication Manager services failed to start after activating a new console certificate 525Number of Views Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 587Number of Views How to install the new RSA ID Plus license 177Number of Views How to create a new ActiveMQ KahaDB for use with AFX in RSA Identity Governance & Lifecycle 355Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to Download OTP Token Seed Files from myRSA RSA Authentication Manager 8.9 Release Notes (January 2026)