Unable to remove privileges for an RSA Via Governance and Lifecycle user
Originally Published: 2016-06-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
After clicking the Remove action for a privilege, the button changes to Removed, but changes back to Remove when the Apply Changes button is pressed.
This behavior occurs when the following steps are taken:
- Select the Users selection on the Users tab.
- Select the Privileges tab.
- Under the Action column choose a privilege to remove by clicking on the Remove button next to the privilege name.
- The button changes to Removed.
- Click on the Apply Changes button to apply the changes.
Instead of the privilege being removed the button changes back to Remove, as in the screen shot below:
Cause
Resolution
There are two ways to determine if entitlements are eligible to be removed from the user Privileges tab.
Option 1
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. This will display how the user entitlement is defined. If the entitlement shows that it is Used By App Roles, then this entitlement is an indirect entitlement and must be removed by removing the parent App Role.
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. If the entitlement details screen shows None for the value of App.Roles, then this is the parent application role and may be removed (or added) as a user privilege. The indirect entitlements that are children of this App Role are listed under the Entitlements section.
Option 2
The second way to determine if entitlements are eligible to be removed from the user Privileges tab is to view the entitlements from the User Access list.- Select Users from the Users tab and then click the Access tab.
- Group the applications by Business Source Name and then select the Aveksa application.
- In the RSA Via Lifecycle and Governance 7.0 role model the user privileges for the Aveksa application are controlled by roles assigned under the Aveksa application.
- Under the Entitlement Type column entitlements that may be removed (or added) to a user are of type app-role and entitlements that are indirect entitlements owned by a parent application role that cannot be removed will be identified by the type ent.
Workaround
- Select the Admin menu and the System.
- Then under the Settings tab select Access Request Manager.
- Set the value to On.
Related Articles
Unable to restart the RSA Authentication Manager services 137Number of Views AFX Connectors remain in a Deployed state, mmc-console fails to start and 'Unable to initialize query handler' acccessing … 681Number of Views RSA MFA Agent 9.0 for PAM - Installation and Configuration Guide for SUSE (Spanish) 16Number of Views RSA Identity Governance & Lifecycle fails to start with "Unable to get avdb connection" message 828Number of Views Initialization error "Unable to register service ReviewService" and "Unable to start local agent" in RSA Identity Governan… 365Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?