
ChrisPope (Customer) to rsaSFDCadmin (RSA): asked a question.
Reintroduced Issue with Re-adding Users to Roles with Membership Rules
We are on IGL 7.5.0 P01 HF01.
History:
For some time now, we have had issues where rehired Users were not
automatically being added to our "Birthright" Roles, all of which have
Membership Rules. I recently did more research on a recent rehire and found
RSA Article [000034931](https://community.rsa.com/t5/securid-governance-
lifecycle/rsa-identity-governance-and-lifecycle-users-do-not-match-
the/ta-p/8166) which explains that there was an issue in 6.8.1+ which caused
IGL to NOT recognize that a User matched the Membership Rule and therefore any
"Role Membership Rule Difference" rule would not automatically add them. This
is precisely what is happening to us in 7.5.0.
The key is that the Users **_were, at one time Members of the Roles and were
removed_**...such as during a Termination. Then when an attempt is made to
automatically re-add them to the Role during a rehire scenario, with a "Role
Membership Rule Difference" rule, IGL fails to recognize that the User matches
the Membership Role and therefore doesn't add the User to the Role. Running
the "Role Membership Rule Difference" seems to be what actually causes IGL to
not recognize the User matches the Membership Rule, so running it is needed to
re-create the issue.
You can see this clearly in this screen shot of our Development environment.
The User obviously matches the simple Membership Rule (Is Terminated = '0')
but the "Matches Membership Rule" is "False":

Current:
On 8/25/2023, I opened RSA Case 02480588 for this and was today (9/7/2023)
informed that the issue is able to be reproduced by RSA in version 7.5.0 and
7.5.2. So, the issue was reintroduced, in at least these two versions...maybe
others. This is the second time we have experienced a re-introduced issue
which was previously fixed.
The RSA Tech suggested I post on this forum for help while he consults with
Professional Services.
What we need is a way to identify when these scenarios occur. I tried to use
SQL to take the Membership Rule of each Role and compare it to the Members but
because the Membership Rules are not true SQL, it cannot be run outside of
IGL. I of course can manually create SQL from the non-SQL Membership Rules,
but I'd like a robust solution that can be run and will automatically include
any/all Roles with Membership Rules, that way if/when new ones are created,
the SQL will automatically include them.
Is anyone else experiencing this issue and/or have a way to identify
occurrences?
Thank you in advance for your help.
History:
For some time now, we have had issues where rehired Users were not
automatically being added to our "Birthright" Roles, all of which have
Membership Rules. I recently did more research on a recent rehire and found
RSA Article [000034931](https://community.rsa.com/t5/securid-governance-
lifecycle/rsa-identity-governance-and-lifecycle-users-do-not-match-
the/ta-p/8166) which explains that there was an issue in 6.8.1+ which caused
IGL to NOT recognize that a User matched the Membership Rule and therefore any
"Role Membership Rule Difference" rule would not automatically add them. This
is precisely what is happening to us in 7.5.0.
The key is that the Users **_were, at one time Members of the Roles and were
removed_**...such as during a Termination. Then when an attempt is made to
automatically re-add them to the Role during a rehire scenario, with a "Role
Membership Rule Difference" rule, IGL fails to recognize that the User matches
the Membership Role and therefore doesn't add the User to the Role. Running
the "Role Membership Rule Difference" seems to be what actually causes IGL to
not recognize the User matches the Membership Rule, so running it is needed to
re-create the issue.
You can see this clearly in this screen shot of our Development environment.
The User obviously matches the simple Membership Rule (Is Terminated = '0')
but the "Matches Membership Rule" is "False":

Current:
On 8/25/2023, I opened RSA Case 02480588 for this and was today (9/7/2023)
informed that the issue is able to be reproduced by RSA in version 7.5.0 and
7.5.2. So, the issue was reintroduced, in at least these two versions...maybe
others. This is the second time we have experienced a re-introduced issue
which was previously fixed.
The RSA Tech suggested I post on this forum for help while he consults with
Professional Services.
What we need is a way to identify when these scenarios occur. I tried to use
SQL to take the Membership Rule of each Role and compare it to the Members but
because the Membership Rules are not true SQL, it cannot be run outside of
IGL. I of course can manually create SQL from the non-SQL Membership Rules,
but I'd like a robust solution that can be run and will automatically include
any/all Roles with Membership Rules, that way if/when new ones are created,
the SQL will automatically include them.
Is anyone else experiencing this issue and/or have a way to identify
occurrences?
Thank you in advance for your help.