Data Access Review for the file share does not show the accounts which have access to file share via the group in RSA Identity Governance and Lifecycle
Originally Published: 2016-06-27
Article Number
Applies To
Issue
The file share below shows access to six groups and one account:
One of the groups has account as its member:
The screen shot below shows Data Access Review and its contents:
This screen shot shows the group DLG_FS_NAS_WholeNAS_Modify whose members are not included in review result:
Resolution
Groups are of two types:
- Managed. Groups that have access to just one data resource. Such groups have the column MANAGEDRES_TYPE set to a value of D in internal table T_GROUPS.
- Non Managed. Groups that have no access to none or more than one data resource.
When the option For each member, review the data resource granted from a data resource group is selected on review definition, the following happens:
- If a group is managed, the relation of group to data resource will not be reviewed. Instead, the access of accounts in the group to the data resource will be reviewed.
- If a group is non managed, the relation of group to data resources will be reviewed. The access derived by accounts in that group to the group’s data resources will not be reviewed.
- So, from number 2 above, it can be said that for a given group, either a group is reviewed (non managed) or accounts in the group (managed) are reviewed but not both at a time.
That is the expected behavior today.
Related Articles
You do not have access to any report results folder 80Number of Views Data Access Collector (DAC) rejects Account Relationships when collecting Account Permissions in RSA Identity Governance &… 149Number of Views RSA Governance & Lifecycle Recipes: Chart - Application - Application Shared Accounts 17Number of Views Account Access and Ownership Review result progress bar does not show 100% though all items are completed in RSA Via Lifec… 79Number of Views How business source filtering works in an account access and ownership review in RSA Identity Governance & Lifecycle 46Number of Views
Trending Articles
RSA Authentication Manager 8.3 Dell 630 and 230 hardware appliance loses ability to access keyboard when running PING 4.0 … RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Setting up the RSA Authentication Agent API 8.5 on a Linux operating system RSA Release Notes for RSA Authentication Manager 8.8 How a Multi-App Entitlement Collector (MAEDC) resolves entitlement relationships with accounts and groups collected by a M…
Don't see what you're looking for?