A completed change request to remove Aveksa Application/Directory entitlements from a user does not remove the access from the user in RSA Identity Governance & Lifecycle
Originally Published: 2020-01-21
Article Number
Applies To
RSA Version/Condition: 7.0.x, 7.1.x, 7.2.x
Issue
In the following example, a request to remove the Aveksa Application: Exceptions Manager entitlement from a user was completed but the access was not removed from the user.
Cause
The fact that the change request shows the access has been removed when it has not been removed has been reported in engineering ticket ACM-103280.
Resolution
This issue is being investigated by the Engineering team in order to provide a permanent resolution in a future release.
Workaround
For example, to resolve the example presented in this RSA Knowledge Base Article:
- Navigate to Users > Users > {user name} > Access tab
- Click on the i icon for the Application : Exceptions Manager entitlement.
- In the pop-up dialog box, click on the Security Scope drop-down.
- Note the Name(s) listed. These are the Applications and/or Directories to which the user is assigned as a Violation Manager.
- Navigate to Resources > Applications/Directories > {Application name} > Edit.
- Scroll to the bottom of the page.
- Click on Violation Manager and change the existing Violation Manager to a different user.
- Click OK > OK to save your changes.
- Navigate to the Users > Users > {user name} > Access tab and note that the Application:Exceptions Manager entitlement has been removed. If the user has no other Aveksa entitlements, the Aveksa application account associated with that user is also removed.
Related Articles
A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer ex… 142Number of Views How to remove all user data stored in the RSA Identity Governance and Lifecycle application database 747Number of Views Unable to remove privileges for an RSA Via Governance and Lifecycle user 83Number of Views How to remove the Edit Users button from Account Review Results in RSA Identity Governance & Lifecycle 61Number of Views A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer ex… 57Number of Views
Trending Articles
Unable to login to RSA Authentication Manager Security Console as super admin Authentication Manager Administration Server with operations console service Fails to Start with "No config.xml Was Found"… Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA Authentication Manager Upgrade Process Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS
Don't see what you're looking for?