User Access Rule is not generating the Change Request due to open violations.
Originally Published: 2019-07-17
Article Number
Applies To
RSA Product/Service Type: Enterprise Software
RSA Version/Condition: 7.1.0
Issue
Resolution
| As per the confirmation from engineering team, observed behavior is by design. If the Rule is not run after collections are run, this will keep the violations in pending status and hence change request will not be generated for open violations. Rules must be processed post collections to move the completed violations to "cleared/Revoked" bucket. Otherwise violations will be in "with pending revocations" bucket. So you can configure the rules to trigger post collections from "Rules > Configurations" section as we had discussed earlier. This will move the violations to closed state. Until the rule got processed violations in completed by CR/ removed will not move to "cleared/Revoked" bucket. Clear bucket: Current violation is no longer a violation either due to change in rule definition that changed user/ entitlement coverage or if those got removed from source with out any change request. Revoked Bucket: items revoked through change request and post collection move the violation to Revoke bucket. Since we have answered the questions and explain the behavior on violations and root cause on why change requests are not created, please let me know if we can proceed with closing this case now. |
Contact Details
Related Articles
Group owner approval is getting assigned to wrong owner in RSA Identity Governance & Lifecycle 42Number of Views Remote Java JMX agent is configured without SSL client and password authentication in RSA Governance & Lifecycle 38Number of Views Attribute change rule creating duplicate change items for users having more than one account with same entitlement in an a… 35Number of Views How approval activity behaves when change request items are grouped by category in RSA Identity Governance & Lifecycle 124Number of Views A completed change request to remove Aveksa Application/Directory entitlements from a user does not remove the access from… 203Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA-2026-10: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide RSA-2026-05: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities RSA Authentication Manager Upgrade Process
Don't see what you're looking for?