Article Number
000036781
Applies To
RSA Product Set: Identity Governance & Lifecycle
RSA Version/Condition: 7.0.2, 7.1.0
Issue
RSA Identity Governance & Lifecycle requests are stuck in a Pending Verification state and the Account value shows with a temporary account name in the format
{nnnnnn} account on {Application Name}. This occurs when the request contains an entitlement for a user where no account currently exists and the application is configured with the Entitlement Requires Account setting set to True. The change request details page shows that the account creation step is Completed. The Entitlement (Entitlement, Group, or Role) is also completed, but the request does not move from"Pending Verification to Verified.
Image description
Cause
This issue may occur if the directory or application is configured with the Entitlement Requires Account setting but there is no account template associated with the directory or application. The request is unable to create the account name for the pending request and without a valid account name the entitlement cannot be verified during the collection.
Resolution
Ensure that a valid account template is associated with the directory or application. From the Resources menu, select the directory or application and then click the Requests tab. Click the Edit Account Template Associations button and select an account template.
Image description
If you are using the Entitlements Require Account feature you
must select an account template that has a valid Pending Account Parameters defined.
Image description
Notes
The system will warn you if you attempt to set the Entitlement Requires Account without a valid account template
Entitlements Require Account cannot be set to YES if there are no account templates with a valid "Name" pending account parameter.
Image description