How to close Open Violations for inactive Segregation of Duties (SoD) and User Access Rules in RSA Identity Governance & Lifecycle
Originally Published: 2020-04-14
Article Number
Applies To
RSA Version/Condition: 7.0.x, 7.1.x, 7.2.x
Issue
- Open violations remain open after the rule has been inactivated.
- Exceptional access remains in effect and on the exceptional access expiration date, the violations become open violations and emails are sent to the remediators to take action.
Tasks
Resolution
- Delete the rule
- Change the rule:
- Edit the SoD or User Access rule.
- Set the status to Active
- Change the Selected users filter to something that is always false (for example, go to Advanced and enter 1=0 in the Where Clause).
- Save the rule changes.
- Run the rule once. This should close all violations.
- Edit the rule again
- Set the status to Inactive
- Remove the false filter.
- Save the rule changes.
Related Articles
RSA MFA Agent 9.0 for PAM - Installation and Configuration Guide for Oracle and RHEL (German) 14Number of Views Update to RSA Authentication Manager Security Patching Process 5Number of Views RSA-2026-11: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities 37Number of Views RSA Announces RSA Authentication Manager 8.9 Patch 2 Hotfix 1 and Updated Web-Tier Server 31Number of Views Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update 2.57KNumber of Views
Trending Articles
Authentication Manager Log Messages (23001-23091) RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog Troubleshooting RSA MFA Agent for Microsoft Windows Customizing the Self-Service Console User Help
Don't see what you're looking for?