Pending accounts which resolve to no known user attribute are expected to be orphaned once collections occur but instead are left in a partially completed state in RSA Identity Governance and Lifecycle
Originally Published: 2017-08-17
Article Number
Applies To
RSA Version/Condition: 7.0.2 GA HF02, 7.0.2 P02
Issue
For example, you have an application called "Animal-Care" with several associated entitlements. If an AD user requests an entitlement in this application, you require an account to also be created in this application using an account template. Let's say you want the account name to be a name not yet known or collected into the Access Certification Manager (ACM). The end-point application also does not know of any attributes collected into ACM. Therefore, there is no known attribute which can be used to resolve this new account upon collection. As such, the desired behavior is, once the ADC and EDC (Entitlement Data Collector) for this application have run, for the entitlements to be associated with this account and for the account to be orphaned so that it may later be identified and mapped to the appropriate user. Instead the following occurs after collection:
In this case the account name is changed to "Professor" which is not a known collected user attribute so it is not able to resolve to the defined user resolution attribute in the collector definition.
- The account shows under the user's access, but not as an orphan.
- The app-roles associated with the account do not show under the user's access tab, which is not expected unless the account is orphaned.
- The account shows the associated app-roles under the application's Accounts tab, as expected.
- The account does not show as orphaned under the application's 'Accounts' tab, which is not expected.
- The user does not show under the application's Who Has Access tab, which is not expected unless the account is orphaned.
- The request is completed
- The account shows under the user's access tab as an orphan.
- The app-roles associated with the account do not show under the user's access tab.
- The account shows the associated app-roles under the application's Accounts tab.
- The account shows as orphaned under the application's Accounts tab.
- The user does not show under the application's "Who Has Access tab" which is correct since the account is orphaned.
- The request is completed.
Cause
Resolution
Workaround
Related Articles
Question: Can unmapped (also known as orphan) events be converted to mapped events 29Number of Views Partially orphaned accounts occur in RSA Identity Governance & Lifecycle when the ADC defines multiple user resolution att… 71Number of Views SQL Collector fails with Java version 1.6 incompatibility error 5Number of Views Fully reviewed Groups in Group Reviews can be set to a None state in RSA Identity Governance & Lifecycle 17Number of Views RSA Governance & Lifecycle Recipes: Report - AD Orphan Accounts 25Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide How to Download OTP Token Seed Files from myRSA Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio…
Don't see what you're looking for?