Fully reviewed Groups in Group Reviews can be set to a None state in RSA Identity Governance & Lifecycle
2 years ago
Originally Published: 2020-01-20
Article Number
000043726
Applies To
RSA Product Set: RSA Identity Governance & Lifecycle 
RSA Version/Condition: 7.1.1
 
Issue
There is an option in RSA Identity Governance & Lifecycle group reviews to undo the review of a group and set it back to None which means not reviewed yet. For example, in the group review below, the members and access of AD Group1 have been fully reviewed and the Review button is set to green. To access a group review go to Reviews > Results > {Review Result Name}.
 
User-added image


A bulk action to set all the review items to None (not reviewed yet) can be performed and set the group review to None, however, the status of the reviewed members and access still shows as 100% fully reviewed.
 
User-added image
 
User-added image

This is also true for a review that has been signed off.
 
User-added image

If a bulk action to set the review state of the group to None takes place, the group review is set to None, however, the status of the reviewed members and access still shows as 100% fully reviewed.
 
User-added image

 
Cause
This is a known issue reported in engineering ticket ACM-100064.
 
Resolution
This issue is resolved in the following RSA Identity Governance & Lifecycle versions and/or patch levels:
  • RSA Identity Governance & Lifecycle 7.1.1 P03
  • RSA Identity Governance & Lifecycle 7.2

This fix is to disallow the application of the None state to a 100% fully reviewed group review item. Given the below scenario, a bulk action to set the below groups to None will have no effect on AD Group1.
 
User-added image

 
Notes
There is no option to cascade the None state to the reviewed members and access. Only the group itself can be set to None (not reviewed yet) and only if it has not been 100% reviewed (after the patch is applied.)