RSA Identity Governance and Lifecycle users do not match the membership rule once removed from the role
Originally Published: 2017-03-13
Article Number
Applies To
RSA Version/Condition: 6.8.1+
Issue
For example:
- Create a role with some membership rule. In this example we are using "users."Is Terminated"=0 or users.Department='Finance'" as the membership rule.
- Add users to the role matching the membership rule and apply the changes.
- Remove a user from the role and commit the changes.
- Try to add the same user back to the role by filtering with matching items and that user is not seen in the list. If we try to search manually with a filter set to All Members, we will be able to see that the user does not match the membership rule. The membership rule condition shows as false rather than true.
Resolution
- V6.8.1 P25,
- V6.9.1 P18,
- V7.0.0 P05,
- V7.0.1 P01,
- V7.0.2
Related Articles
Manually unmapped accounts are not rejected in the collection and remain as an Orphan accounts in RSA Governance & Lifecycle 73Number of Views Terminated Users not correctly removed from Roles in RSA Identity Governance & Lifecycle 115Number of Views "Error - could not execute query" shows instead of the role name when listing roles in RSA Identity Governance & Lifecycle 40Number of Views Role Analytics tab under Missing Required Entitlements displays technical roles as global roles in RSA Identity Governance… 35Number of Views Existing Role memberships later granted through Parent Roles are not revoked when the Role memberships are removed from th… 37Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in… AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?