Terminated Users not correctly removed from Roles in RSA Identity Governance & Lifecycle
Originally Published: 2021-12-06
Article Number
Applies To
RSA Version/Condition: 7.2.0, 7.2.1, 7.5.0, 7.5.2
Issue
The Rule "Role Membership Rule Difference" does not correctly remove "Is Terminated" Users from Global or Business Roles.
Terminated Users still show in the Role as Members even if the Membership Rule has "is Terminated"=0.
Cause
This is a known issue in the following versions:
- RSA Identity Governance & Lifecycle 7.2.0 P09
- RSA Identity Governance & Lifecycle 7.2.1 P05
- RSA Identity Governance & Lifecycle 7.5.0 P01
- SecurID Governance & Lifecycle 7.5.2
Resolution
- RSA Identity Governance & Lifecycle 7.2.0 (please upgrade to get the fix)
- RSA Identity Governance & Lifecycle 7.2.1 P08
- RSA Identity Governance & Lifecycle 7.5.0 P05
- SecurID Governance & Lifecycle 7.5.2 P01
Related Articles
RSA Governance & Lifecycle Recipes: Rule Telemetry - Processing (Running Total) 9Number of Views RSA Identity Governance and Lifecycle users do not match the membership rule once removed from the role 107Number of Views User Picker ignores Include Terminated User flag in Via Lifecycle and Governance 7Number of Views 'Total Number of Users (Terminated)' is missing from the Role Set Analytics tab in versions 7.1.1 P06 and 7.2.0 P01 of RSA… 36Number of Views "Error - could not execute query" shows instead of the role name when listing roles in RSA Identity Governance & Lifecycle 40Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?