Unable to remove privileges for an RSA Via Governance and Lifecycle user
Originally Published: 2016-06-16
Article Number
Applies To
RSA Version/Condition: 7.0
Issue
After clicking the Remove action for a privilege, the button changes to Removed, but changes back to Remove when the Apply Changes button is pressed.
This behavior occurs when the following steps are taken:
- Select the Users selection on the Users tab.
- Select the Privileges tab.
- Under the Action column choose a privilege to remove by clicking on the Remove button next to the privilege name.
- The button changes to Removed.
- Click on the Apply Changes button to apply the changes.
Instead of the privilege being removed the button changes back to Remove, as in the screen shot below:
Cause
Resolution
There are two ways to determine if entitlements are eligible to be removed from the user Privileges tab.
Option 1
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. This will display how the user entitlement is defined. If the entitlement shows that it is Used By App Roles, then this entitlement is an indirect entitlement and must be removed by removing the parent App Role.
- Select the privilege under the Name column and press the information dialog represented by the yellow i icon. If the entitlement details screen shows None for the value of App.Roles, then this is the parent application role and may be removed (or added) as a user privilege. The indirect entitlements that are children of this App Role are listed under the Entitlements section.
Option 2
The second way to determine if entitlements are eligible to be removed from the user Privileges tab is to view the entitlements from the User Access list.- Select Users from the Users tab and then click the Access tab.
- Group the applications by Business Source Name and then select the Aveksa application.
- In the RSA Via Lifecycle and Governance 7.0 role model the user privileges for the Aveksa application are controlled by roles assigned under the Aveksa application.
- Under the Entitlement Type column entitlements that may be removed (or added) to a user are of type app-role and entitlements that are indirect entitlements owned by a parent application role that cannot be removed will be identified by the type ent.
Workaround
- Select the Admin menu and the System.
- Then under the Settings tab select Access Request Manager.
- Set the value to On.
Related Articles
Unable to restart the RSA Authentication Manager services 133Number of Views RSA Identity Governance and Lifecycle users with Group: View All Access are unable to view the groups page 23Number of Views RSA MFA Agent 9.0 for PAM - Installation and Configuration Guide for SUSE (Spanish) 16Number of Views How to remove entitlements of a decommissioned application from user access in RSA Via Lifecycle and Governance 73Number of Views Initialization error "Unable to register service ReviewService" and "Unable to start local agent" in RSA Identity Governan… 360Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?