Termination rule is deleting accounts when rule is not configured to in RSA Identity Governance & Lifecycle
2 years ago
Originally Published: 2019-09-27
Article Number
000041612
Applies To
RSA Product Set: Identity Governance and Lifecycle
RSA Version/Condition: 7.1.X
 
Issue
Sometimes when a Termination Rule is run, it may delete accounts even if the rule is not configured to delete accounts. 

Below are the available actions for a Termination Rule: 
- Disable accounts (excludes shared and service accounts).
- Delete accounts (excludes shared and service accounts).
- Revoke user entitlements (excludes shared and service accounts).
- Shared accounts
- Service accounts


 
Cause
This is expected behaviour, but only if the following scenario. 

When the last entitlement access is removed from an account, the rule will delete that account. 
This occurs due to the account no longer having any entitled access to any applications, and therefore the rule will delete this account to prevent it being an orphaned account. 

If the Termination Rule identifies this account based on the rule's condition, and is configured to only revoke certain access, the account will not be deleted if it still has access to other applications. 
In this scenario, the account will not become orphaned since they still have entitled access.