Empty Termination Change requests created for users that are deleted in RSA Governance & Lifecycle
2 years ago
Article Number
000071967
Applies To
RSA Product Set: RSA Governance & Lifecycle
RSA Version/Condition
  • RSA Governance & Lifecycle 7.5.2 P07
Issue
Termination rule removes the user entitlements then disables and deletes the account.

After the user is deleted, there is an empty change request opened for the user that was deleted in RSA Governance & Lifecycle.
Cause
The problem occurs when a provision termination rule includes an action item and the system processes the rule for a user with only one self-account (not a member of any group).

In this case, only one change request should be created for both delete and revoke entitlement actions;  however  threads are created simultaneously, leading both functions to be treated as different entries in validateExistingCRItemsForSameRule().

This results in the creation of two duplicate change requests for the same item, but the empty change request lacks displayed deleted values.
Resolution
This issue is resolved (no empty change requests created) in the following versions/patches:
  • RSA Governance & Lifecycle 8.0.0 P02