Unauthorized change rule triggered although change request for add access has passed approval phase in RSA Identity Governance & Lifecycle 7.0.2
Originally Published: 2018-12-06
Last Modified: 2022-06-20
Article Number
Applies To
RSA Version/Condition: 7.0.2
Issue
However, when looking at the change request's Approval Phase - Date, approval phase has been completed earlier so it should not have triggered the Unauthorized Change Detection rule.
For example, an Unauthorized Detection Rule was triggered on 27 November 2018 at 2:53 AM. However, as confirmed from the following screenshot of the change request in question, the approval phase has been completed on 7 November 2018, which is 20 days earlier than Unauthorized Detection Rule date.
Tasks
Verify if there are any change requests to remove the same account and if the entitlement combination has been created later than change request for the addition of the same account and entitlement combination.
Resolution
In the following example, a change request to remove access was been created on 22 November. The change request for the addition was created earlier on 5 November. Considering the latest change request for the account and entitlement combination is based on the creation date found in the database (change request to remove access created on 22 November 22 is the latest), this has caused Unauthorized Detection Rule to trigger, which is an expected behavior.
Notes
Related Articles
How does sdshell extract the uid from UNIX after logging on to UNIX and pass the information to ACE/Server? 8Number of Views Provisioning Termination rule is not generating change requests to disable accounts in RSA Identity Governance and Lifecycle 131Number of Views Security scope does not display report names associated with Aveksa Report Result entitlements in RSA Identity Governance … 44Number of Views Apache will not start - Error logged : Init: Pass phrase incorrect 39Number of Views RSA Identity Governance and Lifecycle Change Request created without required Create Account item 127Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?