How user selection and custom account attribute filters work in User Access Reviews in RSA Identity Governance and Lifecycle
Originally Published: 2018-01-10
Article Number
Applies To
RSA Version/Condition: All
Issue
The filter does not seem to work correctly for all users.
In the example below you can see the review result is including one user whose Account Status=LOCKED. Ideally, the user should not have been included in the review result.
Resolution
As shown below the user molly is included in the review because she has an account in another business source whose status is not LOCKED.
One option here is to use an advanced expression to select the users to include that matches the business source(s) used in the access step:
users.id in accounts (accounts."Account Status"<>'LOCKED' and accounts."Application Name"='DAMS') .
After using the advanced filter you can see the account is excluded from review result.
Notes
Related Articles
The workpoint log has daily occurrences of ORA-02049: timeout: distributed transaction waiting for lock errors in RSA Id… 319Number of Views Provide an Offline Emergency Passcode in the User Dashboard 8Number of Views Account summary table export includes the HTML tags that construct the account mapping button in RSA Identity Governance &… 39Number of Views How users are selected for reviews that are triggered by rules in RSA Identity Governance & Lifecycle 25Number of Views How business source filtering works in an account access and ownership review in RSA Identity Governance & Lifecycle 46Number of Views
Trending Articles
RSA Release Notes for RSA Authentication Manager 8.8 Generate a Certificate Signing Request (CSR) for the Web Tier RSA Authentication Manager 8.9 Release Notes (January 2026) RSA SecurID Software Token 4.1.2 and 4.2.1 for Mac OS X displays: No token storage device was detected. Verify that the de… RSA Authentication Manager 8.8 Security Configuration Guide
Don't see what you're looking for?