Partially orphaned accounts occur in RSA Identity Governance & Lifecycle when the ADC defines multiple user resolution attributes from the same target collector
Originally Published: 2019-05-01
Article Number
Applies To
RSA Version/Condition: 7.0.2, 7.1.0
Issue
Partially orphaned accounts are created after Unification. In the example below, note that UserC3 is not displayed as an orphaned account, yet it is not mapped to any user which is the definition of an orphaned account.
Cause
As an example, an IDC collects User Id, Email Address, and Department. An ADC collects AccountName. Three User Resolution rules are defined on these IDC attributes in the ADC definition:
After running the IDC, Unification and ADC, the AccountName resolves to the User Id and correctly maps the users.
If one of the user attributes other than the User Id is modified in the IDC, the problem occurs. In this case, the email address for UserC3 was modified. After running the IDC and Unification, the account is left partially orphaned:
Resolution
Workaround
Related Articles
createChangeRequest Delete Account web serivce call not working in RSA Identity Management and Governance 6.9.1 43Number of Views RSA Governance & Lifecycle Recipes: AFX Telemetry - Total Connectors 27Number of Views RSA Governance & Lifecycle Recipes: Telemetry Chart - Total Collectors 13Number of Views Termination rule fails to detect a user when the user has multiple accounts in a group in RSA Governance & Lifecycle 64Number of Views Trusted Network policy attribute does not work correctly with applications configured after disabling Identity Confidence … 72Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide RSA Authentication Manager 8.9 Setup and Configuration Guide Troubleshooting RSA MFA Agent for Microsoft Windows
Don't see what you're looking for?